waypoint-bio

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to use trust_remote_code=True when loading tokenizers from Outpost Bio's Hugging Face repositories (e.g., outpost-bio/Waypoint-45m). This configuration triggers the download and execution of custom Python logic provided by the repository, creating a vector for remote code execution.
  • [EXTERNAL_DOWNLOADS]: Automated security scans identified https://www.outpost.bio/citations as being on a URL blacklist. Although this domain belongs to the primary vendor, the presence of a blacklist entry necessitates caution. The skill also performs automated downloads of models and datasets from Hugging Face.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external abundance profiles (MetaPhlAn, Kraken2, QIIME 2) through scripts like profiler_to_waypoint.py. It lacks boundary markers for data processed during fine-tuning or embedding tasks. The ingestion points are where untrusted taxonomic data enters the agent's workflow.
  • [DYNAMIC_EXECUTION]: The scripts/vocab_coverage.py utility uses ast.literal_eval to parse Python literal strings from CSV or TSV files. While more secure than eval(), this pattern involves dynamic evaluation of data provided in external input files. The skill also executes custom tokenizer code via the Hugging Face Transformers library as noted in the remote code execution section.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — waypoint-bio