lamindb
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external and untrusted sources, which represents a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in metadata or data records.
- Ingestion points: Data is loaded from CSV and biological H5AD files (
references/annotation-validation.md), as well as REST API responses and external database queries (references/integrations.md). - Boundary markers: The documentation emphasizes the use of schemas and curators (
ln.curators) to validate data structures, providing a functional data-level boundary. - Capability inventory: The skill possesses capabilities to write files (
artifact.save()), synchronize with cloud storage (AWS S3, GCS), and perform database configuration tasks. - Sanitization: External content is standardized against public biological ontologies and validated against registered features before being saved to the lakehouse.
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the
lamindbandbiontylibraries and several domain-specific modules usinguv pip install. - [CREDENTIALS_UNSAFE]: The skill manages sensitive environment variables for cloud and database access, including
AWS_ACCESS_KEY_IDandLAMIN_DB_URL. It includes explicit warnings and instructions to avoid exposing these credentials in logs or terminal output, recommending the use of secret managers. - [PRIVILEGE_ESCALATION]: The setup instructions for multi-user environments include the use of
sudoto create system directories and modify configuration files in protected paths (references/setup-deployment.md). - [DYNAMIC_EXECUTION]: The skill utilizes
joblibfor model serialization and artifact management. Loading artifacts stored as pickles or joblib files from shared or external sources represents a potential risk of unsafe deserialization.
Audit Metadata