onekgpd
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/onekgpd_api.pyperforms network operations todb.dnaerys.orgto fetch genomic variant data. While this is the primary functionality of the skill, the domain is not among the predefined whitelist of common services. No sensitive local files are accessed or transmitted. - [INDIRECT_PROMPT_INJECTION]: The skill ingests genomic annotations and metadata from an external API (
db.dnaerys.org) and local assets. This data is processed by the agent, which has access to theWrite Bashtool. This creates an attack surface where data from the database could theoretically attempt to influence the agent's behavior. - Ingestion points:
scripts/onekgpd_api.py(fetches remote API data) andassets/kgpe.json(processes local metadata). - Boundary markers: The instructions do not provide specific delimiters or warnings to the agent regarding potential instructions embedded within scientific data fields.
- Capability inventory: The agent is permitted to use the
Write Bashtool, allowing for code generation and execution based on the skill's output. - Sanitization: The scripts return structured JSON, but no natural language sanitization is performed on the descriptive annotation fields (such as ClinVar terms or consequences) before they enter the agent's context.
Audit Metadata