pydeseq2

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from CSV, TSV, and H5AD files provided by the user. While the analysis is primarily numerical, metadata columns could potentially contain malicious instructions. The skill environment includes Bash and file modification tools. Structural validation is present in scripts/run_deseq2_analysis.py, though specific prompt-injection sanitization for string data in metadata is not implemented.
  • [DYNAMIC_EXECUTION]: The workflow involves data serialization using the anndata format, which can utilize pickle for certain operations. The skill author includes multiple warnings in SKILL.md, references/api_reference.md, and references/workflow_guide.md cautioning against loading serialized files from untrusted sources, which is a recognized security best practice in the Python data science ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pydeseq2