high-stakes-analytics-decision-lab
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct users to install software from a personal GitHub repository (
https://github.com/limingrui679-design/high-stakes-analytics-decision-lab.git) and an NPM package (limingrui679-design/high-stakes-analytics-decision-lab). These sources are not affiliated with verified organizations. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data files to generate reports and decision briefs, creating a vulnerability to malicious instructions embedded in the input data.
- Ingestion points: Data is loaded from
data/customer_events.csv,data/user_behavior.parquet, anddata/messy_data.csvas shown in the code examples and configuration. - Boundary markers: There are no specific delimiters or instructions for the agent to ignore embedded commands within the processed data.
- Capability inventory: The system executes Python scripts for data orchestration, writes to the local filesystem (
outputs/), and generates markdown reports based on the analysis. - Sanitization: Although quality gates and privacy scans are mentioned for data integrity, there is no evidence of sanitization specifically designed to prevent prompt injection from the input content.
Audit Metadata