magic-data-transformation

Warn

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/derive_columns.py implements custom column calculations using the Python eval() function. Although the skill attempts to restrict the environment and employs a blocklist (blocking keywords like 'import', 'exec', and double underscores), the use of eval() on user-influenced expressions remains a high-risk pattern for potential arbitrary code execution.
  • [DATA_EXFILTRATION]: Features in scripts/deliver_to_db.py and scripts/deliver_to_hf.py enable the transfer of data to external databases and the HuggingFace Hub. While these actions require explicit user confirmation via 'PAUSE gates' and the HuggingFace script includes a credential leak scanner, they represent functional channels for data to leave the local environment.
  • [PROMPT_INJECTION]: The SKILL.md instructions contain a security claim that the skill 'MUST NOT use raw eval()', yet the actual implementation in scripts/derive_columns.py relies on it for several core features. This discrepancy between documented safety constraints and actual code behavior is a significant security concern regarding the skill's transparency.
  • [EXTERNAL_DOWNLOADS]: The skill identifies dependencies on several standard libraries including pandas, numpy, sqlalchemy, and huggingface_hub. These are legitimate data science packages, but their presence facilitates the skill's network and data-handling capabilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 14, 2026, 11:49 AM
Security Audit — agent-trust-hub — magic-data-transformation