un-data-commons

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious instruction overrides, DAN-style jailbreaks, or safety bypass patterns were detected. The skill uses standard instructional language for its intended statistical purpose.\n- [DATA_EXFILTRATION]: The skill does not access sensitive local files or environment variables. It contains explicit security warnings instructing the agent not to transmit model-provider credentials to the external API.\n- [EXTERNAL_DOWNLOADS]: The skill connects to the official UN International Computing Centre (ICC) infrastructure at unsd-datacommons.gcp.un-icc.cloud. This communication is transparently documented and serves the primary function of the skill.\n- [COMMAND_EXECUTION]: The documentation provides example curl commands for direct HTTP communication, but these are for the agent to use as a fallback transport mechanism and do not facilitate arbitrary or malicious command execution.\n- [OBFUSCATION]: No encoded content, hidden URLs, zero-width characters, or homoglyph-based spoofing were identified in the skill's instructions or metadata.\n- [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from external sources, it mitigates potential injection risks by mandating a strict ArcGIS FeatureSet JSON output contract and encouraging schema validation, ensuring data is processed as structured information rather than executable instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 07:33 PM