reactome-database

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the reactome2py Python package via uv pip. This is the official client library for accessing the Reactome database and is considered a safe dependency within the context of biological data research.\n- [COMMAND_EXECUTION]: The skill provides a Python script, scripts/reactome_query.py, designed to execute various commands for querying biological entities, searching pathways, and performing enrichment analysis via Reactome's REST API endpoints.\n- [DATA_EXFILTRATION]: The skill transmits lists of biological identifiers (such as gene symbols or UniProt IDs) and expression datasets to https://reactome.org. This activity is the core intended functionality of the skill and targets a reputable, well-known scientific institution.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of external data files.\n
  • Ingestion points: The skill reads untrusted input from text and TSV files (e.g., gene_list.txt, expression_data.tsv) through the command_analyze function in scripts/reactome_query.py.\n
  • Boundary markers: No specific delimiters or safety instructions are implemented to isolate the content of these input files from the API request logic.\n
  • Capability inventory: The skill is capable of performing network POST requests (requests.post) and writing analysis results to the local filesystem (json.dump).\n
  • Sanitization: Input identifiers are read and used directly in network requests without validation or sanitization beyond whitespace stripping.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 03:10 AM