pylabrobot
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external JSON manifests and CSV transfer tables to generate simulation plans. While this represents an ingestion surface for untrusted data, the implementation in
scripts/_common.pyincludes rigorous validation logic. It enforces strict regular expressions for identifiers, mandatory numeric bounds for volumes and coordinates, and type-checking for all fields. The JSON parser is configured to reject non-finite numbers and duplicate keys, providing strong mitigation against data-driven attacks. - [DYNAMIC_EXECUTION]: The
scripts/inspect_backends.pyutility uses dynamic introspection to check the installed environment. It imports specific modules and classes from thepylabrobotpackage to verify method signatures and availability. This behavior is restricted to a hardcoded allowlist of symbols and is used exclusively for diagnostic purposes to ensure compatibility with the pinned library version. - [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install
PyLabRobotfrom PyPI and references official GitHub repositories for documentation. These references target well-known and trusted package registries and organization repositories, representing standard development workflows.
Audit Metadata