geniml

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external genomic data, including BED files and manifests (CSV/TSV), which serves as a potential attack surface for indirect prompt injection. An attacker might embed instructions in metadata fields or chromosome names to influence the agent's behavior during report generation.
  • Ingestion points: Data enters through scripts/corpus_auditor.py (manifests), scripts/bed_validator.py (BED files), and scripts/tokenizer_compatibility.py (model configs and universes).
  • Boundary markers: The instructions mandate a "safety gate" approach, requiring the agent to run the provided auditing scripts and verify checksums before performing any analysis or model loading.
  • Capability inventory: The bundled Python scripts are dependency-free, do not spawn subprocesses, do not make network requests, and do not perform file writes; they function solely as read-only inspectors that output JSON reports.
  • Sanitization: The scripts/_common.py module implements robust path sanitization, rejecting NUL bytes, parent traversal, URLs, and symlinks. It also includes a custom, non-executable YAML parser to avoid the risks associated with standard deserialization libraries.
  • [EXTERNAL_DOWNLOADS]: The documentation outlines procedures for fetching datasets from BEDbase (api.bedbase.org) and pre-trained models from Hugging Face.
  • The skill documentation explicitly states that bundled scripts do not make network requests and requires the agent to obtain human approval before any download or network-dependent command (e.g., geniml bbclient) is executed.
  • [REMOTE_CODE_EXECUTION]: The references/bedspace.md file describes the process for cloning, compiling, and executing the external StarSpace binary from its archived GitHub repository.
  • This is documented as a legacy reproduction path with prominent warnings regarding the archived status of the code. The documentation provides a pinned commit hash for verification and explicitly instructs the agent to perform compilation only after user approval in an isolated environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — geniml