medchem
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate medicinal chemistry functionality using established open-source libraries (medchem, datamol, RDKit). All processing is local and focused on chemical informatics.
- [EXTERNAL_DOWNLOADS]: The skill instructions include installing standard Python and Conda packages from official registries (PyPI and conda-forge) to set up the necessary scientific environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external molecular data files (SMILES, SDF, CSV). While this constitutes an ingestion surface, the risk is addressed through chemical validation.
- Ingestion points:
load_moleculesfunction inscripts/filter_molecules.pyreads data from CSV, TSV, SDF, and TXT files. - Boundary markers: None explicitly defined for the external data files.
- Capability inventory: Local file reading/writing (CSV/SDF output), Bash access for tool installation and script execution.
- Sanitization: Inputs are passed through
datamol.to_mol, which validates chemical structural integrity, effectively sanitizing the input against non-chemical injection patterns before they are processed by the agent. - [DYNAMIC_EXECUTION]: The medchem query language is a domain-specific language (DSL) for chemical properties and rules. It is parsed using a formal grammar (LALR) rather than an unsafe evaluation of arbitrary code, restricting its capabilities to predefined chemical logic.
Audit Metadata