rdkit
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of external chemical data (SMILES, SDF, MOL files) through RDKit's parsing modules and included scripts. This represents a potential surface for indirect prompt injection if malicious instructions were embedded in chemical metadata or identifiers.\n
- Ingestion points:
Chem.SDMolSupplier,Chem.SmilesMolSupplier, andChem.MolFromSmilesare used in all provided Python scripts and capability documentation to ingest structural data from files.\n - Boundary markers: No specific boundary markers or instruction isolation techniques are mentioned for data parsed into the LLM context.\n
- Capability inventory: The skill includes capabilities for file system reading and writing, molecular property calculation, and fingerprint generation.\n
- Sanitization: The skill emphasizes the use of
Chem.SanitizeMolto validate the chemical integrity of molecules, though this does not directly address LLM-level prompt injection.\n- [DYNAMIC_EXECUTION]: Inreferences/workflows_and_best_practices.md, the skill proactively identifies the security risks associated with Python'spicklemodule, warning users not to load pickle files from untrusted sources. It provides a safer alternative for caching molecular data using RDKit's binary representation combined with Base64 and JSON encoding.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing RDKit using standard package managers (uv,pip,conda) from trusted registries (PyPI, conda-forge). No downloads from unknown or untrusted third-party servers are initiated.
Audit Metadata