Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill is designed for comprehensive scientific data analysis and is generally functional. However, it presents security risks related to processing untrusted data. Specifically, its reference documentation suggests the use of the 'pickle' library for serialized data, which is a known vector for arbitrary code execution. Additionally, the skill's workflow involving the generation of reports from external data files creates a surface for indirect prompt injection, where malicious instructions hidden in data files could influence the agent's behavior.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues
ZeroLeaks
passScore: 93/100 · 2 sections analyzed