pymatgen
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed with a strong security posture, emphasizing local validation and explicit provenance tracking. All identified potential risks are correctly mitigated by the provided scripts and instructions.
- [CREDENTIALS_UNSAFE]: Materials Project API authentication is handled securely through environment variables (MP_API_KEY). The mp_query.py script and _common.py utility include logic to redact these secrets from error messages and prevent them from being included in manifest files or logs.
- [DATA_EXFILTRATION]: File and network operations are strictly controlled. The _common.py utility enforces maximum byte sizes for inputs and outputs, prevents directory traversal via path resolution, and forbids overwriting existing files. Network access is restricted to the official Materials Project endpoint and requires explicit user activation through a dedicated CLI flag.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external structure files (CIF, POSCAR, etc.), which are identified as ingestion points for untrusted data. Risk is mitigated by mandatory boundary instructions for the agent to review all parser warnings, as well as robust sanitization routines including site/byte bounds and strict JSON parsing that rejects duplicate keys or non-finite numbers.
- [DYNAMIC_EXECUTION]: The skill avoids unsafe execution patterns by explicitly forbidding the use of pickle or general object decoders for restoring state, mandating the use of schema-validated JSON and explicit class constructors instead.
Audit Metadata