latchbio-integration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [DYNAMIC_EXECUTION]: The
scripts/inspect_latch_sdk.pyutility usesimportlib.import_moduleto perform local introspection of the Latch SDK. This is used to verify the presence and signatures of specific library symbols (e.g.,@workflow,LPath) and operates exclusively on a hardcoded list of trusted module names, presenting no risk of arbitrary code execution. - [DATA_EXPOSURE]: The skill provides clear instructions on secure credential management. It warns against manual access to sensitive token files (e.g.,
~/.latch/token) and directs users to use the platform's supported OAuth flow and theget_secret()function for handling sensitive data within compute tasks. - [COMMAND_EXECUTION]: The instructions explicitly advise against passing untrusted strings to shell commands. They recommend using structured argument lists with
subprocess.run(..., check=True)as a safer alternative to prevent shell injection vulnerabilities in bioinformatics pipelines. - [INDIRECT_PROMPT_INJECTION]: The skill identifies potential ingestion surfaces where external data (such as Registry records or execution logs) enters the agent's context. It mitigates injection risks by providing specific guidance on data validation, sanitization, and the use of structured execution messages rather than raw data logs for user communication.
Audit Metadata