molfeat

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the molfeat package from PyPI and references the MAP4 fingerprinting tool from a public GitHub repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external molecular data, creating a potential surface for indirect prompt injection.
  • Ingestion points: SMILES strings passed to MoleculeTransformer and FPCalculator in SKILL.md and references/examples.md.
  • Boundary markers: None explicitly defined in the provided instructions to separate data from instructions.
  • Capability inventory: Uses Write and Bash tools for configuration persistence and environment setup.
  • Sanitization: Recommends using datamol to standardize and validate molecules before featurization.
  • [SAFE]: The skill demonstrates security awareness by explicitly warning users to use np.savez instead of pickle for caching to avoid arbitrary code execution vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — molfeat