gtars
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes gtars (Python) and gtars-cli (Rust) from official registries. While these are external dependencies, the skill defines a trust gate requiring immutable version pinning (e.g., gtars==0.9.2) and manual verification of artifact hashes.
- [DYNAMIC_EXECUTION]: The skill handles native extensions (PyO3) and Cargo build scripts. It mitigates risk by providing a local
artifact_inspector.pyscript that hashes and classifies binaries and wheels without loading or executing them, allowing for pre-execution audits. - [INDIRECT_PROMPT_INJECTION]: The skill processes genomic intervals (BED) and sequences (FASTA) which could theoretically contain instructions. This surface is addressed by mandatory local validation using scripts like
bed_validator.pyandtokenizer_manifest.py, which enforce a strict coordinate contract (0-based, half-open, u32 bounds) before any main library call. - [COMMAND_EXECUTION]: The skill uses the
Bashtool for local genomic processing. All execution is mediated through an explicit planning phase (usingexecution_plan.pyandcoverage_preflight.py) which generates deterministic command templates and validates input bounds before any operation is approved.
Audit Metadata