bioinformatics-on-healthomics
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is authored by a known vendor (awslabs) and provides standard infrastructure management capabilities for AWS services.
- [COMMAND_EXECUTION]: The skill includes shell scripts (
setup-healthomics-role.sh,setup-s3-bucket.sh) for automating AWS environment configuration. These scripts are transparent, perform standard administrative tasks using the AWS CLI, and enforce security settings like S3 public access blocks. - [CREDENTIALS_UNSAFE]: The skill promotes secure credential management by instructing users to use AWS Secrets Manager for external registry authentication (Docker Hub) instead of hardcoding sensitive tokens.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external workflow definitions (WDL/Nextflow). This ingestion surface is a standard part of bioinformatics pipelines; the skill identifies the risk and recommends using official linting tools (
LintAHOWorkflowDefinition) to validate definitions before registration. - [EXTERNAL_DOWNLOADS]: References to external container registries (quay.io, public.ecr.aws) are for standard, well-known bioinformatics software repositories and are handled via AWS HealthOmics pull-through cache mechanisms.
Audit Metadata