scientific-db-pubmed-database

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external biomedical data from the PubMed database, creating a potential surface for indirect prompt injection through search results.
  • Ingestion points: Data retrieved from NCBI E-utilities endpoints such as esearch.fcgi and efetch.fcgi (SKILL.md).
  • Boundary markers: The skill does not explicitly define delimiters for the retrieved literature content.
  • Capability inventory: Performs HTTP GET requests using the requests library to fetch data (SKILL.md).
  • Sanitization: Uses standard JSON parsing for API responses, which mitigates basic structural injection.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill performs legitimate network operations to the well-known NCBI E-utilities service.
  • Evidence: The Python implementation in SKILL.md targets https://eutils.ncbi.nlm.nih.gov/entrez/eutils for search queries.
  • Best Practices: Correctley advises storing sensitive credentials like NCBI_API_KEY and NCBI_EMAIL in environment variables rather than hardcoding them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 12:09 AM
Security Audit — agent-trust-hub — scientific-db-pubmed-database