alterlab-matchms
Warn
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill documents and enables the use of load_from_pickle and save_as_pickle. Deserializing data using the Python pickle module is a known security risk as it can lead to arbitrary code execution if the source file is untrusted. Evidence found in SKILL.md and references/importing_exporting.md.
- [EXTERNAL_DOWNLOADS]: The skill provides the load_from_usi function which allows the agent to fetch spectral data from the Global Natural Products Social Molecular Networking (GNPS) repository, a well-known scientific service.
Audit Metadata