locus-to-gene-mapper-skill
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The bundled runner (scripts/map_locus_to_gene.py) directly requests and ingests data from multiple public, user-generated/untrusted endpoints—e.g., the GWAS Catalog (https://www.ebi.ac.uk/gwas/rest/api), EFO/OLS (https://www.ebi.ac.uk/ols4/api), Open Targets GraphQL (https://api.platform.opentargets.org), gnomAD (https://gnomad.broadinstitute.org/api) and NCBI RefSNP—then deterministically interprets that content to compute L2G/coloc/eQTL/burden/coding scores and drive downstream outputs, so third-party content can materially influence tool behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata