harvard-artifacts-etl-streamlit-app

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation instructions require cloning a repository from a personal GitHub account (https://github.com/Manali0711/Harvard-Artifacts-Collection-Data-Engineering-Analytics-App.git). This source is not associated with a verified organization or well-known service.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an automated pipeline that ingests metadata from an external source (Harvard Art Museums API) and processes it for display and storage.
  • Ingestion points: The fetch_artifacts function in SKILL.md fetches records directly from the public API at api.harvardartmuseums.org.
  • Boundary markers: The skill lacks explicit delimiters or instructions for the agent to ignore potentially malicious commands embedded within the artifact metadata (such as titles, cultures, or mediums).
  • Capability inventory: The skill possesses the capability to write to a SQL database (load_to_database), access environment variables for credentials, and render dynamic visualizations via Streamlit and Plotly.
  • Sanitization: While the code uses parameterized SQL queries to prevent SQL injection and uses safe dictionary access with default values, it does not sanitize content against natural language instructions that could influence the AI agent's behavior during data analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — harvard-artifacts-etl-streamlit-app