tamarind

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest tool schemas, descriptions, and API specifications dynamically from the Tamarind Bio platform at runtime. This creates a potential surface where instructions embedded in tool metadata could influence the agent's behavior.
  • Ingestion points: The agent fetches openapi.yaml, llms.txt, and tool definitions from app.tamarind.bio and docs.tamarind.bio to drive discovery and validation.
  • Boundary markers: There are no explicit instructions to the agent to treat fetched metadata as untrusted or to wrap descriptions in safety delimiters.
  • Capability inventory: The skill provides extensive capabilities including computational job submission, batch processing, file management, and results retrieval via REST and MCP interfaces.
  • Sanitization: No documentation or logic is present to sanitize or filter potential instructional content within the fetched metadata before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill fetches live, machine-readable configuration files (OpenAPI 3.0 specs and LLM indices) from official vendor domains (app.tamarind.bio, docs.tamarind.bio) to ensure the agent has the latest tool parameters and endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — tamarind