matchms

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes spectral data from various external sources, establishing a potential vector for indirect prompt injection via malformed metadata.
  • Ingestion points: Data is loaded from local spectral files (MGF, MSP, mzML, mzXML, JSON) and remote accessions through the Metabolomics USI service (https://metabolomics-usi.gnps2.org) as documented in SKILL.md and references/importing_exporting.md.
  • Boundary markers: The processing logic does not utilize explicit delimiters or specialized instructions to isolate spectral metadata fields from the agent's instructional context.
  • Capability inventory: The skill utilizes Bash for runtime verification and environment management, alongside Read, Write, and Edit tools for manipulating spectral libraries.
  • Sanitization: The scripts/library_search.py script implements robust defensive measures by strictly blocking the ingestion of .pickle and .pkl files to prevent remote code execution. It also validates command-line arguments and enforces maximum pair limits to mitigate resource exhaustion attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — matchms