dnanexus-integration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The helper script
scripts/inspect_dxpy.pyutilizesimportlib.import_module()to perform dynamic introspection of the local environment. This is used to verify that thedxpySDK is correctly installed and that required symbols are present before execution. The modules being loaded are hardcoded within the script and correspond to the official DNAnexus library. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the DNAnexus platform, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads
dxapp.jsonmanifests, project names, file paths, and metadata (tags/properties) from the platform API. - Boundary markers: Instructions explicitly direct the agent to treat all platform-derived data as untrusted and verify resolved IDs before performing mutations.
- Capability inventory: The skill environment includes the
dxCLI anddxpySDK, enabling file system operations, network API calls, and subprocess execution. - Sanitization: The operating contract requires passing subprocess arguments as arrays and quoting shell variables to prevent command injection from malicious object names or metadata.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation and use of official DNAnexus tooling, including the
dxpyPython package and thedxCompilerJava executable. These resources are sourced from the official platform repositories and are necessary for the skill's primary function.
Audit Metadata