magic-data-lifecycle

Warn

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The script references/pipeline_template.py utilizes importlib.util.spec_from_file_location and spec.loader.exec_module to dynamically load and execute Python modules from a file path supplied via the --config command-line argument. This allows the agent to execute arbitrary Python code from the local file system.
  • [PROMPT_INJECTION]: The skill's data processing workflow ingests external data formats (CSV, Parquet, JSONL) and performs operations including file system modification and network communication via the HuggingFace Hub. The absence of content sanitization or explicit boundary markers in the data handling logic presents a surface for indirect prompt injection. * Ingestion points: Data reading operations in SKILL.md and pipeline_template.py. * Boundary markers: Not implemented for data contents. * Capability inventory: File writing in the save_checkpoint function and network connectivity via the huggingface_hub library. * Sanitization: No data sanitization or validation of embedded instructions is performed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 14, 2026, 11:49 AM
Security Audit — agent-trust-hub — magic-data-lifecycle