biotech-expert

Warn

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The BioinformaticsPipeline class in references/EXAMPLES.md utilizes subprocess.run with shell=True inside the call_variants method. This allows for the execution of arbitrary shell commands if the input strings are not properly controlled.
  • [DYNAMIC_EXECUTION]: The call_variants method in references/EXAMPLES.md constructs shell commands by joining list elements into a single string (' '.join(cmd)) before executing them via a shell environment. This pattern is susceptible to command injection if variables such as sample_id or file paths contain shell metacharacters like semicolons, pipes, or backticks.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external genomics data, which represents a vulnerability surface for indirect prompt injection.
  • Ingestion points: The BioinformaticsPipeline class (references/EXAMPLES.md) processes external FASTQ, BAM, and VCF files.
  • Boundary markers: There are no boundary markers or instructions provided to the agent to disregard natural language instructions that might be embedded in the metadata or comments of these biological data files.
  • Capability inventory: The skill has access to powerful tools including Bash and Python's subprocess for system-level execution.
  • Sanitization: The provided Python examples lack input validation or path sanitization, which would otherwise mitigate the risk of malicious data triggering unintended system actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 11, 2026, 05:12 AM
Security Audit — agent-trust-hub — biotech-expert