mlflow-python

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is configured to communicate with an external MLflow tracking server located at http://mlflow.eonlabs.com:5000. This domain is not identified as a trusted vendor or well-known service in the security guidelines.
  • [COMMAND_EXECUTION]: The skill executes several bundled Python scripts using the uv run command. These scripts include log_backtest.py, query_experiments.py, create_experiment.py, and get_metric_history.py to perform MLflow operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests and displays data from external sources.
  • Ingestion points: The scripts/log_backtest.py script reads data from external CSV files provided via the --returns argument. Additionally, scripts/query_experiments.py retrieves experiment metadata and run results from the configured MLflow tracking server.
  • Boundary markers: There are no explicit instructions or delimiters in the scripts to signal the agent to ignore potentially malicious content embedded within the returns CSV or the MLflow run data.
  • Capability inventory: The skill uses standard tools like Bash, Read, Grep, and Glob, and it performs network operations via the mlflow library to communicate with the tracking server.
  • Sanitization: Input data in log_backtest.py is processed through Pandas and QuantStats, which primarily treats the data as numeric time-series. Output in query_experiments.py is formatted using the tabulate library for terminal display.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:42 PM
Security Audit — agent-trust-hub — mlflow-python