tooluniverse-drug-mechanism-research

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from multiple external pharmacological and scientific databases such as ChEMBL, OpenTargets, DailyMed, and KEGG. * Ingestion points: Data enters the context through various API calls to external biological databases referenced in SKILL.md. * Boundary markers: The skill instructions provide a reporting template but do not specify delimiters for external content to prevent the model from misinterpreting embedded instructions. * Capability inventory: The skill utilizes tool calls for data retrieval and report generation; no unsafe file system access, arbitrary command execution, or network exfiltration to unknown domains were detected. * Sanitization: No explicit instructions for sanitizing, escaping, or validating the retrieved API data are provided before it is interpolated into the final report.
  • [SAFE]: The skill's functionality is restricted to querying well-known and reputable scientific and regulatory APIs. This behavior is consistent with the skill's primary purpose of biological research, and no patterns of credential theft, obfuscation, or persistence were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:31 AM
Security Audit — agent-trust-hub — tooluniverse-drug-mechanism-research