labarchive-integration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external APIs and local files, which presents a surface for indirect prompt injection.
- Ingestion points:
scripts/notebook_operations.pyparses external ZIP archives (LA containers) and XML manifests; the agent processes XML and JSON responses from LabArchives APIs. - Boundary markers: Instructions in
SKILL.mdandreferences/api_reference.mdexplicitly warn the agent to treat notebook content, comments, and metadata as untrusted data and to ignore any instructions found within them. - Capability inventory: The skill provides local scripts for configuration validation, request signing, and ZIP inspection. The agent context would include network access to official LabArchives endpoints.
- Sanitization: The
scripts/notebook_operations.pyscript implements security bounds, including path traversal prevention, symlink rejection, resource limits (file size, compression ratio, member count), and manual detection of forbidden XML DTDs or entity declarations to prevent XXE attacks. - [EXTERNAL_DOWNLOADS]: The skill references official LabArchives regional API endpoints and documentation sites.
- Evidence: References to
api.labarchives.com,help.labarchives.com, and various regional subdomains (caapi, auapi, etc.). - Context: These are well-known official services necessary for the skill's primary integration purpose.
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute bundled local scripts for setup and request planning.
- Evidence: Documentation of
uv run scripts/setup_config.py,uv run scripts/entry_operations.py, anduv run scripts/notebook_operations.py. - Context: These scripts are part of the skill's local environment and are used to perform offline validation and signature generation without exposing credentials.
Audit Metadata