machine-learning-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as model artifacts and infrastructure configurations which could potentially contain malicious instructions.
  • Ingestion points: The skill accesses model artifacts and infrastructure configs (defined in SKILL.md under Tool Restrictions).
  • Boundary markers: No explicit boundary markers or delimiters are defined for these ingestion points to separate data from instructions.
  • Capability inventory: The skill has capabilities to execute shell commands via Bash and perform file write operations for deployment configurations (SKILL.md).
  • Sanitization: While "Sanitize all prediction inputs" is mentioned in the Best Practices, there is no explicit sanitization or validation mentioned for the infrastructure configurations themselves.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:05 AM
Security Audit — agent-trust-hub — machine-learning-engineer