pathogen-variant-surveillance

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches live pathogen nomenclature data (aliases and notes) from the official Pango designation repository on GitHub. This is documented as necessary for resolving evolving lineage names and is handled via standard JSON/text parsing.
  • [DATA_EXFILTRATION]: Network operations are strictly limited to the scientific LAPIS API instances required for the skill's primary function. No sensitive local files, environment variables, or credentials are accessed or transmitted.
  • [INDIRECT_PROMPT_INJECTION]: The lapis_client.py script includes a robust sanitize function designed to clean data retrieved from external APIs. It strips control characters and collapses white space to prevent a malicious or malformed API response from forging structural elements (like new rows or headers) in the data provided to the agent.
  • [COMMAND_EXECUTION]: The skill does not use subprocess, os.system, or any other shell execution mechanisms. All scientific calculations and data processing are performed directly in Python using standard libraries.
  • [DYNAMIC_EXECUTION]: No usage of eval(), exec(), or unsafe deserialization (like pickle) was found. Data is parsed using the standard json module.
  • [CREDENTIALS_UNSAFE]: The skill requires no API keys or credentials for the public instances it targets, and no secrets are hardcoded in the scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pathogen-variant-surveillance