skills/tenequm/skills/lance-format/Gen Agent Trust Hub

lance-format

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download data and software from external, non-whitelisted sources during setup and tutorials.
  • In references/docs/quickstart/vector-search.md, the agent is directed to fetch the SIFT1M dataset from a university domain using wget ftp://ftp.irisa.fr/local/texmex/corpus/sift.tar.gz.
  • In references/docs/quickstart/index.md, the documentation provides instructions to install beta versions of the library from a Gemfury registry using pip install --extra-index-url https://pypi.fury.io/lance-format pylance, which is a non-standard package source.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building agents that ingest and process external datasets, creating a significant surface for indirect prompt injection.
  • Ingestion points: Data enters the agent's context through lance.dataset(uri) and subsequent to_table() or scanner() calls as documented in references/docs/guide/read_and_write.md.
  • Boundary markers: The documentation does not describe the use of delimiters or specific instructions for the agent to ignore any natural language instructions that might be embedded within the columnar data.
  • Capability inventory: The described execution environment includes full Python script execution via pylance, the ability to write to the local filesystem (e.g., UDF checkpoints mentioned in references/docs/guide/data_evolution.md), and extensive network access for cloud storage providers (AWS S3, GCS, Azure) detailed in references/docs/guide/object_store.md.
  • Sanitization: No mechanisms for sanitizing or validating the content of the ingested data files are discussed or implemented.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 10:08 AM
Security Audit — agent-trust-hub — lance-format