matchms
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes spectral data from various external sources, establishing a potential vector for indirect prompt injection via malformed metadata.
- Ingestion points: Data is loaded from local spectral files (MGF, MSP, mzML, mzXML, JSON) and remote accessions through the Metabolomics USI service (https://metabolomics-usi.gnps2.org) as documented in
SKILL.mdandreferences/importing_exporting.md. - Boundary markers: The processing logic does not utilize explicit delimiters or specialized instructions to isolate spectral metadata fields from the agent's instructional context.
- Capability inventory: The skill utilizes
Bashfor runtime verification and environment management, alongsideRead,Write, andEdittools for manipulating spectral libraries. - Sanitization: The
scripts/library_search.pyscript implements robust defensive measures by strictly blocking the ingestion of.pickleand.pklfiles to prevent remote code execution. It also validates command-line arguments and enforces maximum pair limits to mitigate resource exhaustion attacks.
Audit Metadata