benchling-integration

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data from biological sequence files and Benchling API responses, creating a surface for potential indirect prompt injection attacks.\n
  • Ingestion points: Untrusted data enters the agent's context through Bio.SeqIO.parse (processing FASTA files) in SKILL.md, benchling.dna_sequences.list() (fetching entity registry data), and AWS EventBridge event payloads in references/eventbridge.md.\n
  • Boundary markers: The instructions do not define specific delimiters or boundary markers to isolate external data from the agent's instructions.\n
  • Capability inventory: The skill is granted access to the Bash, Read, Write, and Edit tools as per the SKILL.md frontmatter configuration.\n
  • Sanitization: There is no mention of sanitizing or validating entity names, sequence bases, or event metadata before the agent processes them.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external Python dependencies to interface with the Benchling platform.\n
  • Description: Fetches the benchling-sdk library from the official Python Package Index (PyPI). This is a well-known service and the dependency is appropriate for the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — benchling-integration