scanpy

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard bioinformatics analysis scripts using the well-established scanpy library. All operations involve processing structured RNA-seq data (e.g., .h5ad, .mtx, .csv) and generating visualizations or tabular summaries.
  • [EXTERNAL_DOWNLOADS]: The skill installs necessary Python dependencies using uv pip install. The packages (scanpy, anndata, leidenalg, harmonypy, bbknn, etc.) are well-known, established libraries in the single-cell genomics community. These are standard dependencies for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data files such as .h5ad and .rds. While this represents an ingestion surface, the data consists of numerical gene expression matrices and metadata. There are no patterns of executing instructions embedded within the data. Boundary markers are inherently provided by the AnnData structure, and the tools used (Scanpy/AnnData) are not susceptible to traditional prompt injection via numerical matrices. (Severity: LOW/SAFE)
  • [COMMAND_EXECUTION]: The skill documentation provides guidance for using Rscript to convert R-native single-cell objects to the Python-friendly .h5ad format. These are informative instructions for the user to perform necessary data conversion using official R packages (zellkonverter, Seurat). No arbitrary or silent command execution is performed by the skill itself.
  • [DATA_EXPOSURE]: The skill scripts read from and write to local files provided by the user (input data and output figures/results). No access to sensitive system paths (e.g., SSH keys, credentials) or unauthorized network exfiltration was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scanpy