omero-integration

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill demonstrates extensive security best practices for handling microscopy data and credentials.
  • Credential Management: It explicitly forbids placing passwords in logs, command arguments, or output files. It reads credentials only from specific environment variables and refuses to load .env files to prevent accidental leakage of unrelated secrets.
  • Data Minimization: Instructions and scripts enforce bounded pagination (e.g., caps of 1000 objects), explicit ID selection, and hard limits on string lengths and collection sizes to prevent resource exhaustion and data over-exposure.
  • Metadata Redaction: Bundled scripts like inventory.py and export_image_metadata.py redact names, annotation values, and labels by default, requiring explicit user flags for inclusion.
  • Safe File Operations: The omero_common.py utility implements atomic JSON writes using temporary files and os.replace, while enforcing restrictive 0600 (owner-only) file permissions.
  • Transport Security: The skill defaults to secure=True (SSL) for all communication and provides clear warnings about the limitations of standard hostname verification in the OMERO client.
  • Dependency Safety: External dependencies (omero-py, ZeroC IcePy) and references to Glencoe Software (a known OME partner) are standard in the microscopy domain and are handled according to documented official sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — omero-integration