csv-data-summarizer

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a 'CRITICAL BEHAVIOR REQUIREMENT' section that employs imperative commands to override the agent's default conversational behavior. By forbidding the agent from asking questions or offering options, the skill attempts to bypass standard user interaction guardrails.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from CSV files via Python scripts. It lacks boundary markers to delineate data from instructions and does not mention input sanitization, creating a surface where malicious content in a CSV could influence the agent's logic or outputs (Ingestion: summarize_csv, Capability: pandas and matplotlib execution in analyze.py).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:22 PM
Security Audit — agent-trust-hub — csv-data-summarizer