agent-data-ml-model
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection.
- Ingestion points: The agent is designed to trigger on and process content from various file types including
.csv,.json,.ipynb,.pkl, and.h5files, which are external data sources that may contain untrusted content. - Boundary markers: The instructions do not define clear delimiters or specific instructions for the agent to ignore potentially embedded commands within the machine learning datasets or notebooks it processes.
- Capability inventory: The skill is granted powerful capabilities including
Bashfor shell command execution andWrite/Editfor file system modifications. - Sanitization: There is no evidence of input validation or sanitization routines to prevent the execution of malicious instructions that might be hidden within processed data files.
Audit Metadata