magic-data-synthesis

Warn

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The script scripts/batch_synthesize.py employs the Python eval() function to implement the expression strategy for data transformation. Although the execution environment is constrained by clearing __builtins__, using eval() on user-supplied or agent-generated expressions presents a risk of arbitrary code execution if the configuration file is compromised.
  • [COMMAND_EXECUTION]: The skill frequently invokes shell commands via subprocess.run and subprocess.Popen to interact with the data-designer CLI and other local tools. These operations are core to the skill's functionality for managing data processing pipelines and estimating costs.
  • [PROMPT_INJECTION]: The skill's primary function is to process external data (CSV, Parquet, JSONL) using Large Language Models to fill missing values or generate new columns. This behavior creates a significant surface for indirect prompt injection attacks, where malicious instructions embedded in source data rows could influence the agent's output. The skill includes built-in mitigations such as prompt sanitization, quality thresholds, and validation via LLM judges.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 14, 2026, 11:49 AM
Security Audit — agent-trust-hub — magic-data-synthesis