scvi-tools

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of single-cell genomic data files, creating a vulnerability surface for indirect prompt injection if those files contain malicious instructions in metadata fields.\n- Ingestion points: Data is loaded from external sources using functions such as sc.read_h5ad(), sc.read_visium(), and sc.read_10x_mtx().\n- Boundary markers: There are no explicit instructions or delimiters provided to prevent the agent from following potential natural language instructions embedded within the genomic data objects.\n- Capability inventory: The skill utilizes model training, file writing (model.save()), and local data visualization capabilities.\n- Sanitization: The workflows do not include steps to sanitize or validate metadata fields in the incoming genomic data structures.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the scvi-tools package and several well-known scientific dependencies (scanpy, mudata, scvelo, etc.) from standard registries. It also includes functions that download reference genomes from public biological databases for sequence-aware analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scvi-tools