ncats-arax
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes structured biomedical data and metadata from the external NCATS ARAX API, constituting a surface for indirect prompt injection.
- Ingestion points: The
scripts/arax_client.pyscript retrieves API responses fromarax.transltr.iothrough/openapi.json,/entity, and/queryendpoints. - Boundary markers: The script mediates interaction by parsing JSON responses and generating isolated artifacts (
summary.json,response.json) and formatted text summaries, providing clear boundaries between raw external data and the agent's context. - Capability inventory: The skill writes query artifacts to a local directory and performs outbound HTTPS requests via
urllib.request. It does not possess capabilities for arbitrary command execution or system modification. - Sanitization: Robust sanitization is implemented in
scripts/arax_client.pyvia the_sanitize_textfunction, which removes control characters and truncates strings to 500 characters, effectively mitigating risks from malformed or malicious payloads. - [SAFE]: The skill demonstrates high-quality security practices including the following:
- SSRF Protection: The
validate_base_urlfunction usesipaddress.is_globalto reject private, loopback, and reserved addresses, preventing Server-Side Request Forgery attacks. - Secure Redirects: A custom
SameOriginHttpsRedirectHandleris implemented to reject cross-origin redirects and protocol downgrades (e.g., HTTPS to HTTP). - Secure File Handling: Artifacts are written using atomic operations and restricted file permissions (
0o600), ensuring data integrity and minimizing exposure on the local filesystem. - Validated Network Operations: The skill communicates exclusively with the established biomedical API at
arax.transltr.ioover HTTPS using standard library components.
Audit Metadata