arboreto
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external transcriptomics data files which could be used to influence the agent's behavior if the data is untrusted.
- Ingestion points: Files such as
expression_data.tsvandtf_list.txtare read into the agent's context inscripts/basic_grn_inference.pyand referenced inSKILL.md. - Boundary markers: There are no protective delimiters or instructions to ignore potential commands embedded in the data.
- Capability inventory: The skill allows writing analysis results to the local filesystem and establishing network connections to Dask schedulers.
- Sanitization: Input data is not validated or sanitized for potentially malicious strings or structural anomalies.
- [DATA_EXFILTRATION]: The skill documents and enables network connections to remote Dask schedulers via TCP addresses (e.g.,
tcp://scheduler:8786). This constitutes a network operation to non-whitelisted endpoints, which represents a potential channel for data transmission to external infrastructure.
Audit Metadata