pytdc

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust path validation system in scripts/_common.py using safe_relative_path and safe_directory. These functions ensure that all file reads and writes are restricted to the current workspace, effectively preventing path traversal attacks using absolute paths or parent directory references.
  • [SAFE]: A strict consent model is enforced for all network and storage operations. Operations such as downloading datasets from Harvard Dataverse or fetching model checkpoints require the agent to use explicit CLI flags (--execute and --download), ensuring the user retains control over external data access.
  • [SAFE]: The skill employs bounded input processing to prevent resource exhaustion and denial-of-service. For instance, scripts/benchmark_evaluation.py limits prediction files to 50 MiB, and scripts/molecular_generation.py restricts SMILES inputs to 1 MiB and 500 molecules, while also enforcing character limits on individual strings.
  • [SAFE]: Dynamic loading via importlib.import_module (detected in scripts/load_and_split_data.py, scripts/benchmark_evaluation.py, and scripts/_common.py) is implemented securely. The module names and classes are resolved using hardcoded internal registries or trusted package metadata, preventing the execution of arbitrary or untrusted code.
  • [SAFE]: Data processed at runtime is sanitized and summarized before being returned to the agent. The truncate_value helper in scripts/_common.py ensures that scientific data outputs are bounded and formatted as strict JSON, mitigating risks associated with indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pytdc