scikit-bio

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external biological data files which may contain malicious instructions designed to influence agent behavior.
  • Ingestion points: The skill uses functions like skbio.DNA.read(), skbio.io.read(), Table.read(), and TreeNode.read() to ingest data from formats like FASTA, FASTQ, and BIOM (SKILL.md, references/api_reference.md).
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are specified for data processing.
  • Capability inventory: The skill has access to Bash, Write, Edit, and Read tools, which could be leveraged if an injection is successful.
  • Sanitization: Input is validated for biological correctness by sequence classes, but no security-focused sanitization is present to filter for malicious text.
  • [EXTERNAL_DOWNLOADS]: Installs scikit-bio and its dependencies (including numpy, matplotlib, biom-format, polars, and anndata) using uv pip. These are well-known and legitimate scientific libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scikit-bio