esm

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documentation in references/esm-c-api.md, references/forge-api.md, and references/workflows.md provides implementation examples using the pickle library for caching protein embeddings and checkpointing batch jobs. The use of pickle.load() on local files creates a vulnerability where an attacker with file system access could replace these cache files with malicious payloads to achieve arbitrary code execution upon deserialization.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest untrusted data from external PDB files (e.g., ESMProtein.from_pdb()) and raw sequence inputs. The ingestion of these external scientific data formats, combined with the lack of explicit sanitization or strict boundary markers in the interpolation logic, establishes a surface for potential indirect prompt injection attacks.
  • [EXTERNAL_DOWNLOADS]: The skill and its reference documentation provide instructions for downloading and installing software from external sources. These include standard PyPI installations for the esm and flash-attn packages, as well as installing the SDK directly from the official Biohub GitHub repository using specific commit hashes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — esm