biotech-expert
Warn
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
BioinformaticsPipelineclass inreferences/EXAMPLES.mdutilizessubprocess.runwithshell=Trueinside thecall_variantsmethod. This allows for the execution of arbitrary shell commands if the input strings are not properly controlled. - [DYNAMIC_EXECUTION]: The
call_variantsmethod inreferences/EXAMPLES.mdconstructs shell commands by joining list elements into a single string (' '.join(cmd)) before executing them via a shell environment. This pattern is susceptible to command injection if variables such assample_idor file paths contain shell metacharacters like semicolons, pipes, or backticks. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external genomics data, which represents a vulnerability surface for indirect prompt injection.
- Ingestion points: The
BioinformaticsPipelineclass (references/EXAMPLES.md) processes external FASTQ, BAM, and VCF files. - Boundary markers: There are no boundary markers or instructions provided to the agent to disregard natural language instructions that might be embedded in the metadata or comments of these biological data files.
- Capability inventory: The skill has access to powerful tools including
Bashand Python'ssubprocessfor system-level execution. - Sanitization: The provided Python examples lack input validation or path sanitization, which would otherwise mitigate the risk of malicious data triggering unintended system actions.
Audit Metadata