scvi-tools
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of single-cell genomic data files, creating a vulnerability surface for indirect prompt injection if those files contain malicious instructions in metadata fields.\n- Ingestion points: Data is loaded from external sources using functions such as
sc.read_h5ad(),sc.read_visium(), andsc.read_10x_mtx().\n- Boundary markers: There are no explicit instructions or delimiters provided to prevent the agent from following potential natural language instructions embedded within the genomic data objects.\n- Capability inventory: The skill utilizes model training, file writing (model.save()), and local data visualization capabilities.\n- Sanitization: The workflows do not include steps to sanitize or validate metadata fields in the incoming genomic data structures.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of thescvi-toolspackage and several well-known scientific dependencies (scanpy,mudata,scvelo, etc.) from standard registries. It also includes functions that download reference genomes from public biological databases for sequence-aware analysis.
Audit Metadata