scanpy
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard bioinformatics analysis scripts using the well-established
scanpylibrary. All operations involve processing structured RNA-seq data (e.g., .h5ad, .mtx, .csv) and generating visualizations or tabular summaries. - [EXTERNAL_DOWNLOADS]: The skill installs necessary Python dependencies using
uv pip install. The packages (scanpy,anndata,leidenalg,harmonypy,bbknn, etc.) are well-known, established libraries in the single-cell genomics community. These are standard dependencies for the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data files such as
.h5adand.rds. While this represents an ingestion surface, the data consists of numerical gene expression matrices and metadata. There are no patterns of executing instructions embedded within the data. Boundary markers are inherently provided by theAnnDatastructure, and the tools used (Scanpy/AnnData) are not susceptible to traditional prompt injection via numerical matrices. (Severity: LOW/SAFE) - [COMMAND_EXECUTION]: The skill documentation provides guidance for using
Rscriptto convert R-native single-cell objects to the Python-friendly.h5adformat. These are informative instructions for the user to perform necessary data conversion using official R packages (zellkonverter,Seurat). No arbitrary or silent command execution is performed by the skill itself. - [DATA_EXPOSURE]: The skill scripts read from and write to local files provided by the user (input data and output figures/results). No access to sensitive system paths (e.g., SSH keys, credentials) or unauthorized network exfiltration was detected.
Audit Metadata