lamindb

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external and untrusted sources, which represents a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in metadata or data records.
  • Ingestion points: Data is loaded from CSV and biological H5AD files (references/annotation-validation.md), as well as REST API responses and external database queries (references/integrations.md).
  • Boundary markers: The documentation emphasizes the use of schemas and curators (ln.curators) to validate data structures, providing a functional data-level boundary.
  • Capability inventory: The skill possesses capabilities to write files (artifact.save()), synchronize with cloud storage (AWS S3, GCS), and perform database configuration tasks.
  • Sanitization: External content is standardized against public biological ontologies and validated against registered features before being saved to the lakehouse.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the lamindb and bionty libraries and several domain-specific modules using uv pip install.
  • [CREDENTIALS_UNSAFE]: The skill manages sensitive environment variables for cloud and database access, including AWS_ACCESS_KEY_ID and LAMIN_DB_URL. It includes explicit warnings and instructions to avoid exposing these credentials in logs or terminal output, recommending the use of secret managers.
  • [PRIVILEGE_ESCALATION]: The setup instructions for multi-user environments include the use of sudo to create system directories and modify configuration files in protected paths (references/setup-deployment.md).
  • [DYNAMIC_EXECUTION]: The skill utilizes joblib for model serialization and artifact management. Loading artifacts stored as pickles or joblib files from shared or external sources represents a potential risk of unsafe deserialization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — lamindb