medchem

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate medicinal chemistry functionality using established open-source libraries (medchem, datamol, RDKit). All processing is local and focused on chemical informatics.
  • [EXTERNAL_DOWNLOADS]: The skill instructions include installing standard Python and Conda packages from official registries (PyPI and conda-forge) to set up the necessary scientific environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external molecular data files (SMILES, SDF, CSV). While this constitutes an ingestion surface, the risk is addressed through chemical validation.
  • Ingestion points: load_molecules function in scripts/filter_molecules.py reads data from CSV, TSV, SDF, and TXT files.
  • Boundary markers: None explicitly defined for the external data files.
  • Capability inventory: Local file reading/writing (CSV/SDF output), Bash access for tool installation and script execution.
  • Sanitization: Inputs are passed through datamol.to_mol, which validates chemical structural integrity, effectively sanitizing the input against non-chemical injection patterns before they are processed by the agent.
  • [DYNAMIC_EXECUTION]: The medchem query language is a domain-specific language (DSL) for chemical properties and rules. It is parsed using a formal grammar (LALR) rather than an unsafe evaluation of arbitrary code, restricting its capabilities to predefined chemical logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — medchem