mat-dielectric-response

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external simulation data files.
  • Ingestion points: The script scripts/plot_dielectric.py reads and parses vasprun.xml and OUTCAR files from user-specified directories to extract dielectric spectra.
  • Boundary markers: No delimiters or instructions are provided to the agent to ignore potentially malicious content embedded in the simulation files.
  • Capability inventory: The script performs file system reads, numerical data parsing, and file system writes (saving PNG plots).
  • Sanitization: No sanitization or validation of the content within the VASP output files is performed before processing.
  • [SAFE]: The post-processing script scripts/plot_dielectric.py contains a broken code block at the end of the file. It attempts to use undefined variables (_params_path, _json, _config) and an undefined argument attribute (args.output_dir), which will result in a NameError or AttributeError during execution. This appears to be a leftover code fragment or a configuration error rather than a security threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 04:09 PM