csv-data-summarizer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external CSV data which creates a potential surface for indirect prompt injection. The instructions in SKILL.md emphasize that the agent should act autonomously and proactively ("Do not ask the user", "Directly do", "Immediate execute"), which could cause the agent to follow malicious instructions hidden within a processed file during the analysis phase.
  • Ingestion points: CSV files are read via the pd.read_csv function in analyze.py.
  • Boundary markers: There are no specific delimiters or warnings in the prompts to differentiate between user instructions and the data content being analyzed.
  • Capability inventory: The skill is capable of reading local files and writing visualization images (.png) to the disk.
  • Sanitization: There is no evidence of natural language filtering or sanitization of the data being processed to prevent instruction injection.
  • [COMMAND_EXECUTION]: The skill involves the execution of a local Python script (analyze.py) to perform its primary function of data analysis and chart generation. This is standard functionality for this type of skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — csv-data-summarizer