harvard-artifacts-etl-streamlit-analytics
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to clone a repository from
https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git. This repository belongs to an unverified individual account rather than a trusted organization or well-known service. - [COMMAND_EXECUTION]: The setup instructions include executing shell commands that install and run the code retrieved from the external repository (
pip install -r requirements.txtandstreamlit run app.py). This allows for the execution of arbitrary code from an untrusted source. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the external Harvard Art Museums API.
- Ingestion points: Artifact metadata is fetched via
requests.getinSKILL.md. - Boundary markers: There are no delimiters or warnings to ignore instructions that might be embedded in the artifact data (e.g., in
titleorculturefields). - Capability inventory: The skill has database write capabilities (
cursor.executemany) and interactive UI rendering (st.dataframe,st.plotly_chart). - Sanitization: While the code truncates strings to fit database schema limits (e.g.,
[:500]), it lacks sanitization or filtering to prevent instructions within the data from influencing the agent's behavior during analysis.
Audit Metadata