omero-integration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill demonstrates extensive security best practices for handling microscopy data and credentials.
- Credential Management: It explicitly forbids placing passwords in logs, command arguments, or output files. It reads credentials only from specific environment variables and refuses to load
.envfiles to prevent accidental leakage of unrelated secrets. - Data Minimization: Instructions and scripts enforce bounded pagination (e.g., caps of 1000 objects), explicit ID selection, and hard limits on string lengths and collection sizes to prevent resource exhaustion and data over-exposure.
- Metadata Redaction: Bundled scripts like
inventory.pyandexport_image_metadata.pyredact names, annotation values, and labels by default, requiring explicit user flags for inclusion. - Safe File Operations: The
omero_common.pyutility implements atomic JSON writes using temporary files andos.replace, while enforcing restrictive0600(owner-only) file permissions. - Transport Security: The skill defaults to
secure=True(SSL) for all communication and provides clear warnings about the limitations of standard hostname verification in the OMERO client. - Dependency Safety: External dependencies (
omero-py,ZeroC IcePy) and references to Glencoe Software (a known OME partner) are standard in the microscopy domain and are handled according to documented official sources.
Audit Metadata