tooluniverse-proteomics-data-retrieval
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external metadata, such as dataset summaries and keywords, from scientific repositories like MassIVE and ProteomeXchange.\n
- Ingestion points: Metadata retrieved via the
MassIVE_get_datasetandProteomeXchange_get_datasettools.\n - Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its instructions and potentially malicious content within the external metadata.\n
- Capability inventory: The skill encourages the agent to write and execute Python scripts via Bash to analyze the ingested data, creating a path for malicious content to influence system actions.\n
- Sanitization: No sanitization, validation, or filtering of the external data is required before it is used for analysis or generated reports.\n- [DYNAMIC_EXECUTION]: The skill instructs the agent to "write and run Python code via Bash" for statistical processing and visualization using scientific libraries. While intended for legitimate analysis, this involves the runtime generation and execution of code strings.
Audit Metadata