polars
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- EXTERNAL_DOWNLOADS (LOW): The skill documentation includes an installation command for the
polarsPython library (uv pip install polars). Although Polars is a highly reputable library, it is not from an organization explicitly listed as trusted in the analysis framework, and the installation is unversioned. - PROMPT_INJECTION (LOW): The skill provides functions to read data from external files, creating a surface for indirect prompt injection. Ingestion points:
pl.read_csv,pl.scan_csv,pl.read_parquet, andpl.read_jsoninSKILL.mdandreferences/core_concepts.md. Boundary markers: Absent; data is processed directly without delimiters or instruction-bypass warnings. Capability inventory: Extensive data transformation, parallel execution, and file writing capabilities (write_csv,write_parquet). Sanitization: Absent; examples demonstrate direct loading of files without validation or escaping of content.
Audit Metadata