etetoolkit

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches public taxonomy data from the NCBI (National Center for Biotechnology Information) and GTDB (Genome Taxonomy Database) scientific databases. These downloads are standard features for biological data annotation, target well-known scientific repositories, and are performed without the use of credentials or execution of remote code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external hierarchical tree data in Newick and Nexus formats. While these external files represent a potential ingestion point for indirect instructions, the skill provides extensive validation guidance in its workflows—such as leaf name uniqueness checks, branch length range verification, and Newick parser consistency—to ensure the structural integrity of the data before it is interpreted.
  • [DYNAMIC_EXECUTION]: The ETE 4 library includes a TreePattern matcher capable of evaluating Python expressions for complex topology searches. The skill includes explicit security warnings and developer guidance to avoid constructing these patterns from untrusted input (such as user-provided strings or file content), recommending safer topology-only matching or standard Python predicates for such tasks.
  • [COMMAND_EXECUTION]: The skill includes bundled scripts for tree manipulation and visualization. These scripts are implemented using standard Python libraries and include robust security controls, such as loopback-only binding for the interactive SmartView server unless remote access is explicitly authorized by the user via command-line flags.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — etetoolkit