cobrapy

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes metabolic model data from external files (SBML, JSON, YAML, MATLAB) which could potentially be used to deliver malicious instructions to the agent if the input files are untrusted. \n
  • Ingestion points: Functions like read_sbml_model, load_json_model, load_yaml_model, and load_matlab_model (referenced in SKILL.md and references/api_quick_reference.md) are used to import model structures from external sources. \n
  • Boundary markers: There are no explicit prompt-level delimiters or warnings against embedded instructions in the processed data, though the skill does recommend model validation as a best practice. \n
  • Capability inventory: The skill possesses the capability to write files (e.g., write_sbml_model, to_csv) and execute environment-level commands via uv pip install. \n
  • Sanitization: The documentation suggests using model.slim_optimize() and consistency checks to validate the biological validity of the models.\n- [COMMAND_EXECUTION]: The skill utilizes the environment's Bash tool to perform routine setup tasks, such as installing the required cobra library and optional extensions via uv pip install.\n- [EXTERNAL_DOWNLOADS]: The skill fetches the cobra library from the Python Package Index (PyPI) and is designed to download metabolic models from recognized scientific databases, including the BiGG Models and BioModels repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — cobrapy