scgpt
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill workflow involves processing single-cell datasets and manifests, which serves as an ingestion surface for untrusted data that could theoretically contain malicious instructions.
- Ingestion points: The workflow records dataset sources, AnnData objects, and matrix manifests (SKILL.md).
- Boundary markers: The instructions lack explicit boundary markers or delimiters to differentiate between data content and processing instructions.
- Capability inventory: The skill is instructional and does not provide accompanying scripts; however, it instructs the agent to save files, generate plots, and verify package availability, which are typical agent capabilities.
- Sanitization: There are no defined sanitization or validation steps for the metadata or marker gene information provided in external datasets.
Audit Metadata