mlflow-python
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is configured to communicate with an external MLflow tracking server located at
http://mlflow.eonlabs.com:5000. This domain is not identified as a trusted vendor or well-known service in the security guidelines. - [COMMAND_EXECUTION]: The skill executes several bundled Python scripts using the
uv runcommand. These scripts includelog_backtest.py,query_experiments.py,create_experiment.py, andget_metric_history.pyto perform MLflow operations. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests and displays data from external sources.
- Ingestion points: The
scripts/log_backtest.pyscript reads data from external CSV files provided via the--returnsargument. Additionally,scripts/query_experiments.pyretrieves experiment metadata and run results from the configured MLflow tracking server. - Boundary markers: There are no explicit instructions or delimiters in the scripts to signal the agent to ignore potentially malicious content embedded within the returns CSV or the MLflow run data.
- Capability inventory: The skill uses standard tools like
Bash,Read,Grep, andGlob, and it performs network operations via themlflowlibrary to communicate with the tracking server. - Sanitization: Input data in
log_backtest.pyis processed through Pandas and QuantStats, which primarily treats the data as numeric time-series. Output inquery_experiments.pyis formatted using thetabulatelibrary for terminal display.
Audit Metadata