pkpd-modeling
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external CSV/TSV files, creating a potential surface for indirect prompt injection if those files contain malicious instructions disguised as data.
- Ingestion points: The
read_tablefunction inscripts/_common.pyis the primary entry point for untrusted data across all utility scripts. - Boundary markers: The skill does not explicitly define delimiters to separate ingested data from the agent's internal reasoning or subsequent instructions.
- Capability inventory: The skill is configured with
Read,Write,Edit, andBashtools, providing broad file system and local execution capabilities. - Sanitization: The utility scripts include robust numerical validation (e.g., the
parse_floatandparse_positivefunctions inscripts/_common.py) and strict column requirement checks, which effectively limit the types of data that can be successfully parsed for analysis. - [SAFE]: The skill explicitly operates without network access and uses established scientific libraries.
- The documentation includes clear warnings regarding pharmacological safety and emphasizes that the scripts are modelling aids, not decision-makers.
- No hardcoded credentials or sensitive file paths were detected.
- External package references (e.g.,
numpy,scipy,pharmpy-core,chi-drm) are limited to well-known, legitimate scientific tools.
Audit Metadata