torchdrug

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in scientific formats such as SMILES strings, PDB files, and SDF files which may contain embedded instructions or malformed data designed to influence agent behavior.
  • Ingestion points: data.Molecule.from_smiles, data.Protein.from_pdb, and various datasets classes in SKILL.md and references/datasets.md.
  • Boundary markers: The skill includes an 'Agent operating procedure' that instructs the agent to sanitize molecules and validate inputs, which serves as a mitigation but not a complete prevention against adversarial data.
  • Capability inventory: The skill utilizes Bash for environment setup, Read/Write for managing data and checkpoints, and full Python execution for training.
  • Sanitization: Explicitly mentions sanitizing molecules before computing and validating labels in the Agent Operating Procedure.
  • [DYNAMIC_EXECUTION]: The skill documentation encourages the use of torch.load() and solver.load() for model checkpoints and serialized state in references/core_concepts.md and references/retrosynthesis.md.
  • Evidence: checkpoint = torch.load("pretrained.pth")["model"] and solver.load("solver.pth").
  • Risk: torch.load() relies on pickle for deserialization, which can be exploited to execute arbitrary code if the agent is directed to load a malicious checkpoint file provided by a user or external source.
  • [EXTERNAL_DOWNLOADS]: The skill fetches binaries and configuration from external repositories to set up the Graph Learning environment.
  • Evidence: uv pip install ... --find-links "https://data.pyg.org/whl/torch-2.0.0+cpu.html" in SKILL.md.
  • Status: These downloads target well-known scientific software registries (PyTorch Geometric) and official TorchDrug documentation, which are standard for this domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — torchdrug