ontology-term-resolution

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a suite of tools for biological ontology term resolution and validation. All scripts are written using the Python standard library, minimizing the risk of supply chain attacks or malicious dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves JSON data from reputable and well-known scientific services, including the European Bioinformatics Institute (EBI) at ebi.ac.uk, Bioregistry, and Identifiers.org. These interactions are strictly for data resolution purposes and do not involve remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external scientific data, creating an attack surface for indirect prompt injection. Mandatory Evidence Chain: 1. Ingestion points: Data is ingested from user-provided text strings and metadata files (TSV/CSV) via script arguments. 2. Boundary markers: The instructions do not specify the use of delimiters when the agent handles this untrusted data. 3. Capability inventory: The skill uses Bash to execute scripts that perform network GET requests and file system operations. 4. Sanitization: The provided Python scripts utilize standard library features like argparse for CLI parsing and urllib.parse.quote to ensure input is safely encoded before being used in network requests. Due to these protections and the specialized nature of the tool, this surface is considered a safe component of its intended operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — ontology-term-resolution