biopython

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is primarily designed to ingest and process biological data from external sources, including NCBI databases and user-supplied sequence files (FASTA, GenBank, PDB, XML). This represents an indirect prompt injection surface area.
  • Ingestion points: Untrusted data enters the agent context via Bio.SeqIO.parse, Bio.Entrez.efetch, and Bio.PDB.PDBParser (located in sequence_io.md, databases.md, and structure.md).
  • Boundary markers: The instructions do not define specific prompt boundary markers for biological data content.
  • Capability inventory: The skill possesses the capability to execute shell commands via subprocess.run and perform file-write operations across multiple modules.
  • Sanitization: The documentation explicitly instructs the agent to validate file paths and avoid constructing command arguments from unsanitized user input when using external tools.
  • [COMMAND_EXECUTION]: The skill provides patterns for executing external bioinformatics CLI tools (such as BLAST+, Clustal Omega, and MUSCLE) using Python's subprocess module. These examples correctly utilize argument lists to mitigate command injection risks.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of biological records, sequences, and protein structures from established scientific infrastructure, specifically the National Center for Biotechnology Information (NCBI) and the Protein Data Bank (PDB). These are well-known and trusted services within the life sciences domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — biopython