bids

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/update_schema.py utility fetches the Brain Imaging Data Structure (BIDS) schema and BIDS Extension Proposals (BEPs) list from official community repositories (bids-specification.readthedocs.io and github.com/bids-standard). These are authoritative sources for the standard being supported.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes neuroscience datasets, which involve ingesting metadata from JSON sidecars and TSV files (e.g., participants.tsv, events.tsv). This creates an attack surface where maliciously crafted dataset metadata could attempt to influence the agent's behavior. However, the skill relies on standard community-validated tools like PyBIDS and bids-validator to handle this data.
  • Ingestion points: Dataset metadata files (JSON, TSV) and directory structures processed by BIDSLayout (PyBIDS).
  • Capability inventory: The skill facilitates file organization, conversion (via heudiconv/dcm2bids), and validation.
  • Sanitization: Standard neuroimaging libraries are used for indexing and validation, providing a layer of structure-based filtering.
  • [COMMAND_EXECUTION]: The documentation provides standard CLI workflows for dataset validation and DICOM-to-BIDS conversion using established neuroimaging tools such as heudiconv, dcm2bids, and bids-validator. These are routine operations for the stated purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — bids