geniml
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external genomic data, including BED files and manifests (CSV/TSV), which serves as a potential attack surface for indirect prompt injection. An attacker might embed instructions in metadata fields or chromosome names to influence the agent's behavior during report generation.
- Ingestion points: Data enters through
scripts/corpus_auditor.py(manifests),scripts/bed_validator.py(BED files), andscripts/tokenizer_compatibility.py(model configs and universes). - Boundary markers: The instructions mandate a "safety gate" approach, requiring the agent to run the provided auditing scripts and verify checksums before performing any analysis or model loading.
- Capability inventory: The bundled Python scripts are dependency-free, do not spawn subprocesses, do not make network requests, and do not perform file writes; they function solely as read-only inspectors that output JSON reports.
- Sanitization: The
scripts/_common.pymodule implements robust path sanitization, rejecting NUL bytes, parent traversal, URLs, and symlinks. It also includes a custom, non-executable YAML parser to avoid the risks associated with standard deserialization libraries. - [EXTERNAL_DOWNLOADS]: The documentation outlines procedures for fetching datasets from BEDbase (
api.bedbase.org) and pre-trained models from Hugging Face. - The skill documentation explicitly states that bundled scripts do not make network requests and requires the agent to obtain human approval before any download or network-dependent command (e.g.,
geniml bbclient) is executed. - [REMOTE_CODE_EXECUTION]: The
references/bedspace.mdfile describes the process for cloning, compiling, and executing the externalStarSpacebinary from its archived GitHub repository. - This is documented as a legacy reproduction path with prominent warnings regarding the archived status of the code. The documentation provides a pinned commit hash for verification and explicitly instructs the agent to perform compilation only after user approval in an isolated environment.
Audit Metadata