pylabrobot

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external JSON manifests and CSV transfer tables to generate simulation plans. While this represents an ingestion surface for untrusted data, the implementation in scripts/_common.py includes rigorous validation logic. It enforces strict regular expressions for identifiers, mandatory numeric bounds for volumes and coordinates, and type-checking for all fields. The JSON parser is configured to reject non-finite numbers and duplicate keys, providing strong mitigation against data-driven attacks.
  • [DYNAMIC_EXECUTION]: The scripts/inspect_backends.py utility uses dynamic introspection to check the installed environment. It imports specific modules and classes from the pylabrobot package to verify method signatures and availability. This behavior is restricted to a hardcoded allowlist of symbols and is used exclusively for diagnostic purposes to ensure compatibility with the pinned library version.
  • [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install PyLabRobot from PyPI and references official GitHub repositories for documentation. These references target well-known and trusted package registries and organization repositories, representing standard development workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pylabrobot