high-stakes-analytics-decision-lab

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct users to install software from a personal GitHub repository (https://github.com/limingrui679-design/high-stakes-analytics-decision-lab.git) and an NPM package (limingrui679-design/high-stakes-analytics-decision-lab). These sources are not affiliated with verified organizations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data files to generate reports and decision briefs, creating a vulnerability to malicious instructions embedded in the input data.
  • Ingestion points: Data is loaded from data/customer_events.csv, data/user_behavior.parquet, and data/messy_data.csv as shown in the code examples and configuration.
  • Boundary markers: There are no specific delimiters or instructions for the agent to ignore embedded commands within the processed data.
  • Capability inventory: The system executes Python scripts for data orchestration, writes to the local filesystem (outputs/), and generates markdown reports based on the analysis.
  • Sanitization: Although quality gates and privacy scans are mentioned for data integrity, there is no evidence of sanitization specifically designed to prevent prompt injection from the input content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — high-stakes-analytics-decision-lab