opentrons-integration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill supports the ingestion of untrusted data via CSV runtime parameters as described in
references/protocol_authoring.md. \n - Ingestion points: Data enters through the
add_csv_fileparameter method.\n - Boundary markers: The skill explicitly instructs the agent to "Reject invalid CSV rows before generating any commands" and validate all values.\n
- Capability inventory: The skill uses
Bashfor simulation andWritefor protocol file generation.\n - Sanitization: Documentation requires manual parsing and range validation of all operator-supplied data before issuing robot instructions.\n- [COMMAND_EXECUTION]: The skill uses shell commands to invoke the
opentrons_simulatetool viauv runfor local protocol validation. This is a core feature of the skill designed to ensure physical safety by verifying code logic before robot deployment.\n- [EXTERNAL_DOWNLOADS]: The skill references official Opentrons software and documentation hosted on GitHub and PyPI. These resources are from the primary vendor and are used for standard environment setup and technical reference.
Audit Metadata