setup-cell2location-remote-tool

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the 'tuplatform-connect' package from 'https://connect.aiscientist.tools/downloads/tuplatform_connect-0.3.0-py3-none-any.whl'. This is a vendor-owned resource (mims-harvard) and the installation command includes a SHA-256 hash verification, which is a security best practice.
  • [CREDENTIALS_SAFE]: The skill correctly instructs the user to store sensitive tokens like 'TOOLUNIVERSE_API_TOKEN' and 'TOOLUNIVERSE_SERVICE_KEY' in protected environments or restricted local files (0600 permissions), rather than passing them as command-line arguments.
  • [COMMAND_EXECUTION]: The skill uses shell commands for environment setup and tool deployment. These operations are transparent, scoped to the tool's scientific purpose, and do not involve suspicious execution patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes scientific data files (H5AD format) as input. While this is an ingestion point for external data, it is a standard part of the tool's intended functionality and is restricted to local relative paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:20 AM
Security Audit — agent-trust-hub — setup-cell2location-remote-tool