anndata

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external biological data files (.h5ad, .zarr, .csv, etc.), creating an attack surface for indirect prompt injection.\n
  • Ingestion points: The agent is instructed to read various file formats including .h5ad, .zarr, .csv, .loom, .mtx, and .xlsx (SKILL.md, references/io_operations.md).\n
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate external data from the agent's control logic.\n
  • Capability inventory: The skill requires Read, Write, Edit, and Bash tools, and includes code for remote network requests using urllib and fsspec (references/io_operations.md).\n
  • Sanitization: The documentation explicitly provides examples for validating hostname and protocol safety before executing remote downloads.\n- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform Python package management via uv pip install (SKILL.md).\n- [EXTERNAL_DOWNLOADS]: The skill provides procedures and code samples for downloading data from remote HTTPS and S3 locations (references/io_operations.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — anndata