datamol

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests molecular data from external URLs and cloud storage providers, creating a potential surface for adversarial instructions embedded in file content or metadata to influence agent behavior. \n
  • Ingestion points: Functions such as dm.read_sdf and dm.open_df documented in references/io_module.md support remote paths. \n
  • Boundary markers: Documentation in SKILL.md and references/core_workflows.md provides guidelines for confirming remote operations and using cloud paths only when requested. \n
  • Capability inventory: The skill allows file writing and command execution, supporting remote data persistence. \n
  • Sanitization: While standardizing chemical structures, the skill does not provide specific sanitization for non-chemical text or instructions in data files. \n- [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of the datamol package and related cloud backends (s3fs, gcsfs) from official registries. \n- [COMMAND_EXECUTION]: The agent is directed to perform environment setup and package management using uv pip install as described in the SKILL.md installation section. \n- [DATA_EXFILTRATION]: Support for cloud providers (S3, GCS) enables reading and writing data to external endpoints. The documentation mitigates risk by explaining that credentials are used locally and advising path verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — datamol