data-transformation

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: Analysis of the skill instructions confirms they are legitimate and documentation-focused. The skill includes best-practice safety warnings for shell operations to prevent data loss.\n- [COMMAND_EXECUTION]: The skill uses the dasel binary and standard shell commands like mv and cat to perform data transformations and file management tasks consistent with its stated purpose.\n- [EXTERNAL_DOWNLOADS]: References to external sites (daseldocs.tomwright.me and GitHub) point to official and reputable sources associated with the dasel open-source project.\n- [PROMPT_INJECTION]: The skill processes structured data from external files which presents an attack surface for indirect prompt injection. Ingestion points: local data files via -f flag or stdin. Boundary markers: absent. Capability inventory: dasel execution, shell command execution, file read/write operations. Sanitization: absent. This risk is inherent to data transformation tools and is considered safe in this instructional context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 08:41 AM