galaxy-workflow-development

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process external Galaxy workflow (.ga) and test configuration (.yml) files. This creates an indirect prompt injection surface where malicious instructions could be embedded in metadata or annotations within these files to influence agent behavior.- [COMMAND_EXECUTION]: The skill provides multiple Python script templates and shell command examples (planemo, curl, grep) to be executed by the agent or user. These are intended for workflow validation, metadata extraction, and file cleaning tasks.- [EXTERNAL_DOWNLOADS]: Recommends downloading workflow files and configurations from the galaxyproject organization on GitHub and datasets from Zenodo, which are considered trusted and well-known sources.- [CREDENTIALS_UNSAFE]: The documentation includes examples of using the GALAXY_API_KEY environment variable and placeholders like YOUR_API_KEY for authenticating with Galaxy servers. These are standard practices for API interaction and do not involve hardcoded secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 02:00 AM