biopython
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is primarily designed to ingest and process biological data from external sources, including NCBI databases and user-supplied sequence files (FASTA, GenBank, PDB, XML). This represents an indirect prompt injection surface area.
- Ingestion points: Untrusted data enters the agent context via
Bio.SeqIO.parse,Bio.Entrez.efetch, andBio.PDB.PDBParser(located insequence_io.md,databases.md, andstructure.md). - Boundary markers: The instructions do not define specific prompt boundary markers for biological data content.
- Capability inventory: The skill possesses the capability to execute shell commands via
subprocess.runand perform file-write operations across multiple modules. - Sanitization: The documentation explicitly instructs the agent to validate file paths and avoid constructing command arguments from unsanitized user input when using external tools.
- [COMMAND_EXECUTION]: The skill provides patterns for executing external bioinformatics CLI tools (such as BLAST+, Clustal Omega, and MUSCLE) using Python's
subprocessmodule. These examples correctly utilize argument lists to mitigate command injection risks. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download of biological records, sequences, and protein structures from established scientific infrastructure, specifically the National Center for Biotechnology Information (NCBI) and the Protein Data Bank (PDB). These are well-known and trusted services within the life sciences domain.
Audit Metadata