arboreto

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external transcriptomics data files which could be used to influence the agent's behavior if the data is untrusted.
  • Ingestion points: Files such as expression_data.tsv and tf_list.txt are read into the agent's context in scripts/basic_grn_inference.py and referenced in SKILL.md.
  • Boundary markers: There are no protective delimiters or instructions to ignore potential commands embedded in the data.
  • Capability inventory: The skill allows writing analysis results to the local filesystem and establishing network connections to Dask schedulers.
  • Sanitization: Input data is not validated or sanitized for potentially malicious strings or structural anomalies.
  • [DATA_EXFILTRATION]: The skill documents and enables network connections to remote Dask schedulers via TCP addresses (e.g., tcp://scheduler:8786). This constitutes a network operation to non-whitelisted endpoints, which represents a potential channel for data transmission to external infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — arboreto