scientist-low
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses standard, high-reputation libraries (pandas, matplotlib) for data processing and visualization.
- [SAFE]: The skill's functionality is limited to reading local CSV files and writing images to a local directory, with no network access or external command execution.
- [SAFE]: Indirect Prompt Injection surface analysis: 1. Ingestion point: The skill is designed to read from local files like 'data.csv'. 2. Boundary markers: No delimiters or ignore instructions are provided for processed data. 3. Capability inventory: Python file reading (pandas.read_csv) and file writing (matplotlib.savefig). 4. Sanitization: No data sanitization is performed. While this creates a surface for indirect prompt injection, it is the primary intended function of a data explorer and involves no high-risk capabilities.
Audit Metadata