pkpd-modeling

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external CSV/TSV files, creating a potential surface for indirect prompt injection if those files contain malicious instructions disguised as data.
  • Ingestion points: The read_table function in scripts/_common.py is the primary entry point for untrusted data across all utility scripts.
  • Boundary markers: The skill does not explicitly define delimiters to separate ingested data from the agent's internal reasoning or subsequent instructions.
  • Capability inventory: The skill is configured with Read, Write, Edit, and Bash tools, providing broad file system and local execution capabilities.
  • Sanitization: The utility scripts include robust numerical validation (e.g., the parse_float and parse_positive functions in scripts/_common.py) and strict column requirement checks, which effectively limit the types of data that can be successfully parsed for analysis.
  • [SAFE]: The skill explicitly operates without network access and uses established scientific libraries.
  • The documentation includes clear warnings regarding pharmacological safety and emphasizes that the scripts are modelling aids, not decision-makers.
  • No hardcoded credentials or sensitive file paths were detected.
  • External package references (e.g., numpy, scipy, pharmpy-core, chi-drm) are limited to well-known, legitimate scientific tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pkpd-modeling