datamol
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests molecular data from external URLs and cloud storage providers, creating a potential surface for adversarial instructions embedded in file content or metadata to influence agent behavior. \n
- Ingestion points: Functions such as
dm.read_sdfanddm.open_dfdocumented inreferences/io_module.mdsupport remote paths. \n - Boundary markers: Documentation in
SKILL.mdandreferences/core_workflows.mdprovides guidelines for confirming remote operations and using cloud paths only when requested. \n - Capability inventory: The skill allows file writing and command execution, supporting remote data persistence. \n
- Sanitization: While standardizing chemical structures, the skill does not provide specific sanitization for non-chemical text or instructions in data files. \n- [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of the
datamolpackage and related cloud backends (s3fs,gcsfs) from official registries. \n- [COMMAND_EXECUTION]: The agent is directed to perform environment setup and package management usinguv pip installas described in theSKILL.mdinstallation section. \n- [DATA_EXFILTRATION]: Support for cloud providers (S3, GCS) enables reading and writing data to external endpoints. The documentation mitigates risk by explaining that credentials are used locally and advising path verification.
Audit Metadata