folklore-variant-evidence

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation includes a curl example for making JSON-RPC calls to a remote service. This is used to demonstrate how to programmatically interact with the Folklore MCP endpoint.
  • [EXTERNAL_DOWNLOADS]: The skill connects to api.helena.bio to fetch gene-disease associations and scientific evidence. This external network communication is necessary for the skill's operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external scientific sources which could theoretically contain adversarial content.
  • Ingestion points: The tools search_variant_evidence, search_variant_literature, and search_literature_corpus fetch content from external bioinformatics and literature databases.
  • Boundary markers: The skill contains specific instructions to 'Enforce the input boundary' to prevent the inclusion of sensitive patient data.
  • Capability inventory: The skill performs network-based data retrieval to query scientific evidence.
  • Sanitization: The instructions require the agent to filter out all patient-specific identifiers, phenotypes, and clinical records from its queries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — folklore-variant-evidence