rowan

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted chemical data such as SMILES strings and PDB files, which could serve as a vector for indirect prompt injection if the inputs contain malicious instructions or exploit underlying parsers.
  • Ingestion points: Chemical molecules are ingested via SMILES strings in various functions (e.g., rowan.Molecule.from_smiles) and protein structures are uploaded from local files (rowan.upload_protein) or IDs, as documented in SKILL.md and references/workflow_catalog.md.
  • Boundary markers: The skill instructions do not specify explicit delimiters or "ignore instructions" prompts when handling these external data inputs.
  • Capability inventory: The skill includes capabilities to write files to the local system (e.g., dock_result.best_pose.write("best_pose.pdb") in references/end_to_end_example.md) and perform network requests to the Rowan API.
  • Sanitization: The platform performs molecule validation, and the instructions recommend using RDKit for local validation before submission, providing some protection against malformed data.
  • [EXTERNAL_DOWNLOADS]: The skill installs the rowan-python library and mentions dependencies like rdkit and pandas. These are standard scientific packages required for the skill's primary functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — rowan