gtars

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes gtars (Python) and gtars-cli (Rust) from official registries. While these are external dependencies, the skill defines a trust gate requiring immutable version pinning (e.g., gtars==0.9.2) and manual verification of artifact hashes.
  • [DYNAMIC_EXECUTION]: The skill handles native extensions (PyO3) and Cargo build scripts. It mitigates risk by providing a local artifact_inspector.py script that hashes and classifies binaries and wheels without loading or executing them, allowing for pre-execution audits.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes genomic intervals (BED) and sequences (FASTA) which could theoretically contain instructions. This surface is addressed by mandatory local validation using scripts like bed_validator.py and tokenizer_manifest.py, which enforce a strict coordinate contract (0-based, half-open, u32 bounds) before any main library call.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool for local genomic processing. All execution is mediated through an explicit planning phase (using execution_plan.py and coverage_preflight.py) which generates deterministic command templates and validates input bounds before any operation is approved.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — gtars