pubmed-gene-drug-research

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill defines workflows that ingest data from external sources (NCBI, PubChem, and PubMed) using tools such as search_gene, search_compound, and search_clinvar.
  • Ingestion points: Data enters the agent context through search results and literature summaries from external databases.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious content embedded within the retrieved scientific data.
  • Capability inventory: The skill is restricted to read-only information retrieval. It does not include tools for file system access, network requests to arbitrary domains, or command execution.
  • Sanitization: There is no evidence of validation or sanitization of the content retrieved from the external databases before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 08:24 PM
Security Audit — agent-trust-hub — pubmed-gene-drug-research