pysam
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied genomic files (BAM, VCF, etc.), which represents a potential surface for indirect prompt injection.\n
- Ingestion points: Bundled scripts such as
alignment_qc.pyandvariant_summary.pyread user-provided genomic files from the local filesystem.\n - Boundary markers: Data parsing relies on HTSlib's implementation of standard biological file formats; the skill does not implement specific LLM boundary markers for these data streams.\n
- Capability inventory: The skill has the ability to write files and execute bioinformatics commands through the
pysam.samtoolsandpysam.bcftoolswrappers.\n - Sanitization: File parsing is performed by the HTSlib library. The skill documentation explicitly recommends using parameterized API calls rather than constructing shell commands from untrusted input.\n- [COMMAND_EXECUTION]: The skill utilizes the
pysamlibrary to executesamtoolsandbcftoolscommands.\n - Evidence: Documented use of
pysam.samtools.sort,pysam.samtools.index, andpysam.bcftools.indexacross the reference guides and scripts.\n - Context: These calls are standard bioinformatics operations. The skill includes explicit security guidance to prevent shell injection by passing arguments as separate strings and avoiding shell command evaluation.\n- [EXTERNAL_DOWNLOADS]: The skill documents how to access remote genomic data and reference sequences.\n
- Evidence: Mentions of
REF_PATH,REF_CACHE, and HTTPS URLs for data access are found in the performance and CRAM reference documentation.\n - Context: These are standard industry practices for genomic analysis. The skill author notes that the underlying library has disabled implicit remote fetching by default to improve security and auditability.
Audit Metadata