un-data-commons
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No malicious instruction overrides, DAN-style jailbreaks, or safety bypass patterns were detected. The skill uses standard instructional language for its intended statistical purpose.\n- [DATA_EXFILTRATION]: The skill does not access sensitive local files or environment variables. It contains explicit security warnings instructing the agent not to transmit model-provider credentials to the external API.\n- [EXTERNAL_DOWNLOADS]: The skill connects to the official UN International Computing Centre (ICC) infrastructure at
unsd-datacommons.gcp.un-icc.cloud. This communication is transparently documented and serves the primary function of the skill.\n- [COMMAND_EXECUTION]: The documentation provides examplecurlcommands for direct HTTP communication, but these are for the agent to use as a fallback transport mechanism and do not facilitate arbitrary or malicious command execution.\n- [OBFUSCATION]: No encoded content, hidden URLs, zero-width characters, or homoglyph-based spoofing were identified in the skill's instructions or metadata.\n- [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from external sources, it mitigates potential injection risks by mandating a strict ArcGIS FeatureSet JSON output contract and encouraging schema validation, ensuring data is processed as structured information rather than executable instructions.
Audit Metadata