magic-data-synthesis
Warn
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The script
scripts/batch_synthesize.pyemploys the Pythoneval()function to implement theexpressionstrategy for data transformation. Although the execution environment is constrained by clearing__builtins__, usingeval()on user-supplied or agent-generated expressions presents a risk of arbitrary code execution if the configuration file is compromised. - [COMMAND_EXECUTION]: The skill frequently invokes shell commands via
subprocess.runandsubprocess.Popento interact with thedata-designerCLI and other local tools. These operations are core to the skill's functionality for managing data processing pipelines and estimating costs. - [PROMPT_INJECTION]: The skill's primary function is to process external data (CSV, Parquet, JSONL) using Large Language Models to fill missing values or generate new columns. This behavior creates a significant surface for indirect prompt injection attacks, where malicious instructions embedded in source data rows could influence the agent's output. The skill includes built-in mitigations such as prompt sanitization, quality thresholds, and validation via LLM judges.
Audit Metadata