bioinformatics-on-healthomics

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is authored by a known vendor (awslabs) and provides standard infrastructure management capabilities for AWS services.
  • [COMMAND_EXECUTION]: The skill includes shell scripts (setup-healthomics-role.sh, setup-s3-bucket.sh) for automating AWS environment configuration. These scripts are transparent, perform standard administrative tasks using the AWS CLI, and enforce security settings like S3 public access blocks.
  • [CREDENTIALS_UNSAFE]: The skill promotes secure credential management by instructing users to use AWS Secrets Manager for external registry authentication (Docker Hub) instead of hardcoding sensitive tokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external workflow definitions (WDL/Nextflow). This ingestion surface is a standard part of bioinformatics pipelines; the skill identifies the risk and recommends using official linting tools (LintAHOWorkflowDefinition) to validate definitions before registration.
  • [EXTERNAL_DOWNLOADS]: References to external container registries (quay.io, public.ecr.aws) are for standard, well-known bioinformatics software repositories and are handled via AWS HealthOmics pull-through cache mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 12:46 AM
Security Audit — agent-trust-hub — bioinformatics-on-healthomics