deepchem
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external molecular data files (CSV, SDF, FASTA) using various loaders defined in
references/api_reference.mdand implemented in thescripts/directory. This creates a standard surface for indirect prompt injection if the ingested data contains unexpected content that the agent is subsequently tasked to process. - Ingestion points:
CSVLoader,SDFLoader, andFASTALoaderare used inscripts/graph_neural_network.py,scripts/predict_solubility.py, andscripts/transfer_learning.pyto import external datasets. - Boundary markers: The instructions do not define specific delimiters or warnings for the agent when interpreting the content of these external files.
- Capability inventory: The skill utilizes the
Bashtool to execute Python scripts that perform complex computations and can write results to the filesystem. - Sanitization: The 'Agent operating procedure' in
SKILL.mdexplicitly instructs the agent to 'sanitize molecules before computing', which serves as a mitigation measure. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download of pre-trained machine learning models and benchmark datasets from established, well-known services.
- Evidence:
scripts/transfer_learning.pyandreferences/workflows.mddescribe the use ofdc.models.HuggingFaceModelto fetch models such asseyonec/ChemBERTa-zinc-base-v1,ibm/MoLFormer-XL-both-10pct, andRostlab/prot_bertfrom Hugging Face. - Evidence:
references/api_reference.mdandreferences/core_capabilities.mddescribe the use ofdc.molnet.load_*functions to fetch standard MoleculeNet benchmark datasets via the DeepChem project's infrastructure. - Context: These operations target well-known repositories and services essential for the skill's primary purpose in scientific research.
Audit Metadata