alterlab-matchms

Warn

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents and enables the use of load_from_pickle and save_as_pickle. Deserializing data using the Python pickle module is a known security risk as it can lead to arbitrary code execution if the source file is untrusted. Evidence found in SKILL.md and references/importing_exporting.md.
  • [EXTERNAL_DOWNLOADS]: The skill provides the load_from_usi function which allows the agent to fetch spectral data from the Global Natural Products Social Molecular Networking (GNPS) repository, a well-known scientific service.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 12:46 AM
Security Audit — agent-trust-hub — alterlab-matchms