waypoint-bio
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to use
trust_remote_code=Truewhen loading tokenizers from Outpost Bio's Hugging Face repositories (e.g.,outpost-bio/Waypoint-45m). This configuration triggers the download and execution of custom Python logic provided by the repository, creating a vector for remote code execution. - [EXTERNAL_DOWNLOADS]: Automated security scans identified
https://www.outpost.bio/citationsas being on a URL blacklist. Although this domain belongs to the primary vendor, the presence of a blacklist entry necessitates caution. The skill also performs automated downloads of models and datasets from Hugging Face. - [INDIRECT_PROMPT_INJECTION]: The skill processes external abundance profiles (MetaPhlAn, Kraken2, QIIME 2) through scripts like
profiler_to_waypoint.py. It lacks boundary markers for data processed during fine-tuning or embedding tasks. The ingestion points are where untrusted taxonomic data enters the agent's workflow. - [DYNAMIC_EXECUTION]: The
scripts/vocab_coverage.pyutility usesast.literal_evalto parse Python literal strings from CSV or TSV files. While more secure thaneval(), this pattern involves dynamic evaluation of data provided in external input files. The skill also executes custom tokenizer code via the Hugging Face Transformers library as noted in the remote code execution section.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata