alphagenome

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external genomic data files (VCF, TSV, CSV) for variant analysis, creating a standard attack surface for indirect prompt injection via data ingestion.
  • Ingestion points: Genomic data is ingested from local files through the --input argument in the analysis scripts (scripts/atlas_query.py and scripts/score_variants.py).
  • Boundary markers: The scripts utilize structured parsing for VCF and delimited formats, validating coordinate and base formatting.
  • Capability inventory: The skill has access to the Bash tool for environment setup, can write results to the filesystem, and performs network requests to AlphaGenome gRPC API endpoints.
  • Sanitization: Genomic variants are validated against expected regex patterns and reference alleles, ensuring data integrity before processing.
  • [EXTERNAL_DOWNLOADS]: The skill fetches reference genome annotations from Google Cloud Storage (storage.googleapis.com) and installs the core alphagenome package from PyPI. These resources originate from a well-known and trusted service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — alphagenome