lance-format
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download data and software from external, non-whitelisted sources during setup and tutorials.
- In
references/docs/quickstart/vector-search.md, the agent is directed to fetch the SIFT1M dataset from a university domain usingwget ftp://ftp.irisa.fr/local/texmex/corpus/sift.tar.gz. - In
references/docs/quickstart/index.md, the documentation provides instructions to install beta versions of the library from a Gemfury registry usingpip install --extra-index-url https://pypi.fury.io/lance-format pylance, which is a non-standard package source. - [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building agents that ingest and process external datasets, creating a significant surface for indirect prompt injection.
- Ingestion points: Data enters the agent's context through
lance.dataset(uri)and subsequentto_table()orscanner()calls as documented inreferences/docs/guide/read_and_write.md. - Boundary markers: The documentation does not describe the use of delimiters or specific instructions for the agent to ignore any natural language instructions that might be embedded within the columnar data.
- Capability inventory: The described execution environment includes full Python script execution via
pylance, the ability to write to the local filesystem (e.g., UDF checkpoints mentioned inreferences/docs/guide/data_evolution.md), and extensive network access for cloud storage providers (AWS S3, GCS, Azure) detailed inreferences/docs/guide/object_store.md. - Sanitization: No mechanisms for sanitizing or validating the content of the ingested data files are discussed or implemented.
Audit Metadata