benchling-integration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data from biological sequence files and Benchling API responses, creating a surface for potential indirect prompt injection attacks.\n
- Ingestion points: Untrusted data enters the agent's context through
Bio.SeqIO.parse(processing FASTA files) inSKILL.md,benchling.dna_sequences.list()(fetching entity registry data), and AWS EventBridge event payloads inreferences/eventbridge.md.\n - Boundary markers: The instructions do not define specific delimiters or boundary markers to isolate external data from the agent's instructions.\n
- Capability inventory: The skill is granted access to the
Bash,Read,Write, andEdittools as per theSKILL.mdfrontmatter configuration.\n - Sanitization: There is no mention of sanitizing or validating entity names, sequence bases, or event metadata before the agent processes them.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external Python dependencies to interface with the Benchling platform.\n
- Description: Fetches the
benchling-sdklibrary from the official Python Package Index (PyPI). This is a well-known service and the dependency is appropriate for the skill's stated purpose.
Audit Metadata