magic-data-profiling

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/detect_all_issues.py executes other local scripts in the skill's package using subprocess.run. This is an orchestration pattern for a multi-script toolkit and is implemented using list-based arguments which mitigates shell injection risks.
  • [DATA_EXFILTRATION]: No network operations or unauthorized data transfer patterns were detected. Data operations are limited to reading input files and writing local reports/visualizations as specified by user-provided paths.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns attempting to override agent behavior or bypass safety filters. It explicitly instructs the agent to use code for deterministic profiling rather than LLM inference, which is a defensive design choice.
  • [SAFE]: The skill uses well-known, trusted Python libraries (pandas, numpy, scipy) and follows professional development practices for data science workflows, including sampling and error handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 11:49 AM
Security Audit — agent-trust-hub — magic-data-profiling