diffdock

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts/setup_check.py script uses the __import__ function to verify if required scientific libraries are installed in the environment.
  • The implementation uses a hardcoded list of standard packages (e.g., numpy, torch, rdkit) rather than user-supplied input, making the usage benign for its intended purpose of environment validation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external molecular data formats including PDB files, SMILES strings, and CSV batch files.
  • Ingestion points: Protein structure files (PDB), ligand descriptions (SMILES/SDF/MOL2), and batch configuration CSVs as documented in SKILL.md and scripts/prepare_batch_csv.py.
  • Boundary markers: The instructions do not specify explicit delimiters for the content of processed molecular files.
  • Capability inventory: The skill uses bash to execute inference.py (DiffDock), and the scripts/analyze_results.py script reads output files to extract confidence scores.
  • Sanitization: scripts/prepare_batch_csv.py employs RDKit for SMILES structure validation and Pandas for CSV schema verification, reducing the risk of processing malformed data.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes standard installation procedures that involve fetching external resources.
  • It references the official DiffDock source code repository (github.com/gcorso/DiffDock) and a Docker image from a recognized research group (rbgcsail/diffdock).
  • These downloads are standard for the scientific domain and facilitate the core functionality of the docking tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — diffdock