tamarind
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest tool schemas, descriptions, and API specifications dynamically from the Tamarind Bio platform at runtime. This creates a potential surface where instructions embedded in tool metadata could influence the agent's behavior.
- Ingestion points: The agent fetches
openapi.yaml,llms.txt, and tool definitions fromapp.tamarind.bioanddocs.tamarind.bioto drive discovery and validation. - Boundary markers: There are no explicit instructions to the agent to treat fetched metadata as untrusted or to wrap descriptions in safety delimiters.
- Capability inventory: The skill provides extensive capabilities including computational job submission, batch processing, file management, and results retrieval via REST and MCP interfaces.
- Sanitization: No documentation or logic is present to sanitize or filter potential instructional content within the fetched metadata before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill fetches live, machine-readable configuration files (OpenAPI 3.0 specs and LLM indices) from official vendor domains (
app.tamarind.bio,docs.tamarind.bio) to ensure the agent has the latest tool parameters and endpoints.
Audit Metadata