data-scientist

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from various sources including SQL databases (PostgreSQL, BigQuery, Snowflake) and data files via pandas. While this creates a surface for indirect prompt injection if external data contains malicious instructions, no specific exploits are present in the skill code.
  • Ingestion points: SQL query results, CSV/JSON data processing via pandas/NumPy, and API interactions.
  • Boundary markers: The instructions do not define explicit delimiters for untrusted data or 'ignore instructions' warnings.
  • Capability inventory: The persona is authorized to perform complex data manipulation, Python/R script execution, and model deployment operations.
  • Sanitization: No explicit sanitization or validation logic is defined for the data ingestion process.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or malicious persistence mechanisms was found. The technical capabilities listed are standard for data science workflows and are described as persona capabilities rather than immediate executable commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:34 PM
Security Audit — agent-trust-hub — data-scientist