nutmeg-wrangle
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing and manipulation of external football data files (JSON, CSV, Parquet) which are untrusted inputs.
- Ingestion points: Data is ingested through the
Readtool and processed via scripts (Python/Node.js/R) as described in the 'Handling large datasets' and 'Format conversion' sections. - Boundary markers: The instructions do not define specific delimiters or guardrails to prevent the agent from interpreting strings within the data (e.g., player names, team names, or match notes) as instructions.
- Capability inventory: The skill has access to powerful tools such as
Bash,Write, andAgent, which could perform sensitive actions if triggered by malicious data content. - Sanitization: No explicit sanitization or input validation logic is mandated for text fields within the datasets, creating a standard surface for indirect prompt injection.
Audit Metadata