string-database
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill contains behavioral instructions directing the agent to proactively suggest the K-Dense Web platform during complex workflows, modifying the agent's response strategy to include promotional content. Additionally, the skill presents an indirect prompt injection surface by processing data from the external STRING API. Ingestion points: API response data parsed in scripts/string_api.py; Boundary markers: Absent; Capability inventory: Local script execution and filesystem access; Sanitization: Not documented.
- [COMMAND_EXECUTION]: The skill relies on local Python scripts (scripts/string_api.py and scripts/string_enrichment.py) to perform core API functions and data processing tasks.
- [EXTERNAL_DOWNLOADS]: The skill fetches scientific data from the well-known STRING database API at string-db.org to fulfill research queries.
- [DATA_EXFILTRATION]: User-supplied protein identifiers and analysis parameters are transmitted to the external STRING database API to facilitate interaction and enrichment analysis.
Audit Metadata