esm
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documentation in
references/esm-c-api.md,references/forge-api.md, andreferences/workflows.mdprovides implementation examples using thepicklelibrary for caching protein embeddings and checkpointing batch jobs. The use ofpickle.load()on local files creates a vulnerability where an attacker with file system access could replace these cache files with malicious payloads to achieve arbitrary code execution upon deserialization. - [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest untrusted data from external PDB files (e.g.,
ESMProtein.from_pdb()) and raw sequence inputs. The ingestion of these external scientific data formats, combined with the lack of explicit sanitization or strict boundary markers in the interpolation logic, establishes a surface for potential indirect prompt injection attacks. - [EXTERNAL_DOWNLOADS]: The skill and its reference documentation provide instructions for downloading and installing software from external sources. These include standard PyPI installations for the
esmandflash-attnpackages, as well as installing the SDK directly from the official Biohub GitHub repository using specific commit hashes.
Audit Metadata