pathml

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions include several shell commands for environment setup, including package installation using uv pip and system dependency management using apt-get and brew.
  • [PRIVILEGE_ESCALATION]: Setup instructions recommend using sudo apt-get on Linux systems to install native prerequisites such as openslide-tools and openjdk-17-jdk.
  • [EXTERNAL_DOWNLOADS]: The skill references downloading pre-trained ONNX models from Hugging Face for Mesmer and HoVer-Net inference. It also mentions optional dataset downloads from the University of Warwick (PanNuke) and Zenodo (DeepFocus). These operations are documented as requiring explicit user consent.
  • [DYNAMIC_EXECUTION]: The pathml.datasets.EntityDataset class utilizes PyTorch's default deserialization (weights_only=False), which can execute arbitrary code when loading untrusted .pt artifacts. The skill explicitly warns against loading untrusted files and provides bundled planning tools that validate metadata without loading executable model code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes whole-slide images (OpenSlide/Bio-Formats), CSV manifests, and JSON spatial data, which serve as ingestion points for untrusted content.
  • Ingestion points: WSI slide files (SKILL.md, references/image_loading.md), CSV manifests (scripts/slide_manifest.py), and JSON graph data (scripts/validate_spatial_schema.py).
  • Boundary markers: The instructions mandate strict de-identification protocols and the use of pseudonymous identifiers to isolate patient data from the analysis environment.
  • Capability inventory: The skill has access to file writing, Bash execution for CLI tools, and image processing capabilities.
  • Sanitization: The provided Python scripts perform strict validation, including regular expression checks for identifiers, path validation to prevent symlink and URL injection, and numeric range enforcement for image dimensions and resource limits.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pathml