gget

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests sequences and gene lists from external files, which could theoretically contain malicious instructions targeting the agent's logic.
  • Ingestion points: read_fasta in scripts/batch_sequence_analysis.py and read_gene_list in scripts/enrichment_pipeline.py process user-provided FASTA and CSV/text files.
  • Boundary markers: The skill does not implement specific boundary markers or instruction-ignoring warnings when processing this data.
  • Capability inventory: Capabilities include extensive network access to bioinformatics APIs, local file system writes for results, and package installation via gget setup.
  • Sanitization: The scripts validate biological formats but do not sanitize for potential prompt injection content.
  • [EXTERNAL_DOWNLOADS]: The skill includes setup commands for downloading large-scale scientific datasets and installing module-specific dependencies.
  • Evidence: gget setup alphafold downloads approximately 4GB of model parameters, and gget setup cellxgene installs necessary Python packages via pip/uv.
  • [COMMAND_EXECUTION]: The skill interacts with the local environment to manage dependencies and execute specialized bioinformatics binaries.
  • Evidence: The gget setup command utilizes package managers (pip or uv) to install software, and modules like muscle and diamond invoke external alignment tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — gget