mat-dielectric-response
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external simulation data files.
- Ingestion points: The script
scripts/plot_dielectric.pyreads and parsesvasprun.xmlandOUTCARfiles from user-specified directories to extract dielectric spectra. - Boundary markers: No delimiters or instructions are provided to the agent to ignore potentially malicious content embedded in the simulation files.
- Capability inventory: The script performs file system reads, numerical data parsing, and file system writes (saving PNG plots).
- Sanitization: No sanitization or validation of the content within the VASP output files is performed before processing.
- [SAFE]: The post-processing script
scripts/plot_dielectric.pycontains a broken code block at the end of the file. It attempts to use undefined variables (_params_path,_json,_config) and an undefined argument attribute (args.output_dir), which will result in aNameErrororAttributeErrorduring execution. This appears to be a leftover code fragment or a configuration error rather than a security threat.
Audit Metadata