agent-data-ml-model

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection.
  • Ingestion points: The agent is designed to trigger on and process content from various file types including .csv, .json, .ipynb, .pkl, and .h5 files, which are external data sources that may contain untrusted content.
  • Boundary markers: The instructions do not define clear delimiters or specific instructions for the agent to ignore potentially embedded commands within the machine learning datasets or notebooks it processes.
  • Capability inventory: The skill is granted powerful capabilities including Bash for shell command execution and Write/Edit for file system modifications.
  • Sanitization: There is no evidence of input validation or sanitization routines to prevent the execution of malicious instructions that might be hidden within processed data files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — agent-data-ml-model