reactome-database
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
reactome2pyPython package viauv pip. This is the official client library for accessing the Reactome database and is considered a safe dependency within the context of biological data research.\n- [COMMAND_EXECUTION]: The skill provides a Python script,scripts/reactome_query.py, designed to execute various commands for querying biological entities, searching pathways, and performing enrichment analysis via Reactome's REST API endpoints.\n- [DATA_EXFILTRATION]: The skill transmits lists of biological identifiers (such as gene symbols or UniProt IDs) and expression datasets tohttps://reactome.org. This activity is the core intended functionality of the skill and targets a reputable, well-known scientific institution.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of external data files.\n - Ingestion points: The skill reads untrusted input from text and TSV files (e.g.,
gene_list.txt,expression_data.tsv) through thecommand_analyzefunction inscripts/reactome_query.py.\n - Boundary markers: No specific delimiters or safety instructions are implemented to isolate the content of these input files from the API request logic.\n
- Capability inventory: The skill is capable of performing network POST requests (
requests.post) and writing analysis results to the local filesystem (json.dump).\n - Sanitization: Input identifiers are read and used directly in network requests without validation or sanitization beyond whitespace stripping.
Audit Metadata