molfeat
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
molfeatpackage from PyPI and references the MAP4 fingerprinting tool from a public GitHub repository. - [INDIRECT_PROMPT_INJECTION]: The skill processes external molecular data, creating a potential surface for indirect prompt injection.
- Ingestion points: SMILES strings passed to
MoleculeTransformerandFPCalculatorinSKILL.mdandreferences/examples.md. - Boundary markers: None explicitly defined in the provided instructions to separate data from instructions.
- Capability inventory: Uses
WriteandBashtools for configuration persistence and environment setup. - Sanitization: Recommends using
datamolto standardize and validate molecules before featurization. - [SAFE]: The skill demonstrates security awareness by explicitly warning users to use
np.savezinstead ofpicklefor caching to avoid arbitrary code execution vulnerabilities.
Audit Metadata