13c-metabolic-flux

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the 'mfapy' package from a specific Git revision on GitHub ('github.com/fumiomatsuda/mfapy.git'). While the dependency is pinned to an immutable commit hash for reproducibility, it originates from a source outside of the primary official package registries.
  • [DYNAMIC_EXECUTION]: The metabolic flux engine ('mfapy') generates numerical functions at runtime to perform isotope simulations. To mitigate potential injection risks into these generated functions, the skill's adapter logic ('_mfa_model.py') enforces strict alphanumeric validation on all user-supplied metabolite and reaction identifiers.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes metabolic models and measurement data provided in JSON format, which constitutes a potential attack surface for indirect prompt injection.
  • Ingestion points: Input data is read from JSON files specified by the user via command-line arguments and parsed in 'scripts/_mfa_model.py'.
  • Boundary markers: The skill uses strict JSON schema enforcement and restricts identifier characters and lengths.
  • Capability inventory: The skill is limited to numerical fitting and simulation using scientific libraries; it does not invoke shell commands with user-supplied data or perform network operations.
  • Sanitization: All identifiers are validated against a regular expression ('[A-Za-z][A-Za-z0-9]{0,39}') to ensure they do not contain malicious instructions or code.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — 13c-metabolic-flux