opentrons-integration

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill supports the ingestion of untrusted data via CSV runtime parameters as described in references/protocol_authoring.md. \n
  • Ingestion points: Data enters through the add_csv_file parameter method.\n
  • Boundary markers: The skill explicitly instructs the agent to "Reject invalid CSV rows before generating any commands" and validate all values.\n
  • Capability inventory: The skill uses Bash for simulation and Write for protocol file generation.\n
  • Sanitization: Documentation requires manual parsing and range validation of all operator-supplied data before issuing robot instructions.\n- [COMMAND_EXECUTION]: The skill uses shell commands to invoke the opentrons_simulate tool via uv run for local protocol validation. This is a core feature of the skill designed to ensure physical safety by verifying code logic before robot deployment.\n- [EXTERNAL_DOWNLOADS]: The skill references official Opentrons software and documentation hosted on GitHub and PyPI. These resources are from the primary vendor and are used for standard environment setup and technical reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — opentrons-integration