ncats-arax

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured biomedical data and metadata from the external NCATS ARAX API, constituting a surface for indirect prompt injection.
  • Ingestion points: The scripts/arax_client.py script retrieves API responses from arax.transltr.io through /openapi.json, /entity, and /query endpoints.
  • Boundary markers: The script mediates interaction by parsing JSON responses and generating isolated artifacts (summary.json, response.json) and formatted text summaries, providing clear boundaries between raw external data and the agent's context.
  • Capability inventory: The skill writes query artifacts to a local directory and performs outbound HTTPS requests via urllib.request. It does not possess capabilities for arbitrary command execution or system modification.
  • Sanitization: Robust sanitization is implemented in scripts/arax_client.py via the _sanitize_text function, which removes control characters and truncates strings to 500 characters, effectively mitigating risks from malformed or malicious payloads.
  • [SAFE]: The skill demonstrates high-quality security practices including the following:
  • SSRF Protection: The validate_base_url function uses ipaddress.is_global to reject private, loopback, and reserved addresses, preventing Server-Side Request Forgery attacks.
  • Secure Redirects: A custom SameOriginHttpsRedirectHandler is implemented to reject cross-origin redirects and protocol downgrades (e.g., HTTPS to HTTP).
  • Secure File Handling: Artifacts are written using atomic operations and restricted file permissions (0o600), ensuring data integrity and minimizing exposure on the local filesystem.
  • Validated Network Operations: The skill communicates exclusively with the established biomedical API at arax.transltr.io over HTTPS using standard library components.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — ncats-arax