magic-data-transformation
Warn
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/derive_columns.pyimplements custom column calculations using the Pythoneval()function. Although the skill attempts to restrict the environment and employs a blocklist (blocking keywords like 'import', 'exec', and double underscores), the use ofeval()on user-influenced expressions remains a high-risk pattern for potential arbitrary code execution. - [DATA_EXFILTRATION]: Features in
scripts/deliver_to_db.pyandscripts/deliver_to_hf.pyenable the transfer of data to external databases and the HuggingFace Hub. While these actions require explicit user confirmation via 'PAUSE gates' and the HuggingFace script includes a credential leak scanner, they represent functional channels for data to leave the local environment. - [PROMPT_INJECTION]: The
SKILL.mdinstructions contain a security claim that the skill 'MUST NOT use raw eval()', yet the actual implementation inscripts/derive_columns.pyrelies on it for several core features. This discrepancy between documented safety constraints and actual code behavior is a significant security concern regarding the skill's transparency. - [EXTERNAL_DOWNLOADS]: The skill identifies dependencies on several standard libraries including
pandas,numpy,sqlalchemy, andhuggingface_hub. These are legitimate data science packages, but their presence facilitates the skill's network and data-handling capabilities.
Audit Metadata