13c-metabolic-flux
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the 'mfapy' package from a specific Git revision on GitHub ('github.com/fumiomatsuda/mfapy.git'). While the dependency is pinned to an immutable commit hash for reproducibility, it originates from a source outside of the primary official package registries.
- [DYNAMIC_EXECUTION]: The metabolic flux engine ('mfapy') generates numerical functions at runtime to perform isotope simulations. To mitigate potential injection risks into these generated functions, the skill's adapter logic ('_mfa_model.py') enforces strict alphanumeric validation on all user-supplied metabolite and reaction identifiers.
- [INDIRECT_PROMPT_INJECTION]: The skill processes metabolic models and measurement data provided in JSON format, which constitutes a potential attack surface for indirect prompt injection.
- Ingestion points: Input data is read from JSON files specified by the user via command-line arguments and parsed in 'scripts/_mfa_model.py'.
- Boundary markers: The skill uses strict JSON schema enforcement and restricts identifier characters and lengths.
- Capability inventory: The skill is limited to numerical fitting and simulation using scientific libraries; it does not invoke shell commands with user-supplied data or perform network operations.
- Sanitization: All identifiers are validated against a regular expression ('[A-Za-z][A-Za-z0-9]{0,39}') to ensure they do not contain malicious instructions or code.
Audit Metadata