gtars
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS] (SAFE): The skill utilizes standard package managers (pip/uv and cargo) for installation from official registries. It also provides a method to fetch genomic datasets from bedbase.org, a legitimate scientific resource.\n- [DATA_EXPOSURE] (SAFE): File system interactions are limited to reading and writing genomic data files (BED, TSV, FASTA, WIG) as specified by the user. No attempts to access sensitive system directories (e.g., ~/.ssh, ~/.aws) or environment variables were found.\n- [COMMAND_EXECUTION] (SAFE): The skill's CLI functionality is focused on genomic processing tasks such as coverage generation, overlap detection, and fragment splitting, which are consistent with its stated purpose.\n- [Indirect Prompt Injection] (SAFE): The skill ingests untrusted external genomic data. Although this is a potential injection surface, it is the primary purpose of the tool. Evidence Chain: 1. Ingestion points: gtars.RegionSet.from_bed, gtars.RefgetStore.from_fasta, and gtars bbcache fetch. 2. Boundary markers: Not mentioned. 3. Capability inventory: Genomic processing, file writing, and CLI execution. 4. Sanitization: Standard file parsing logic is used; no specific security sanitization is documented for NL injection, as the data is primarily processed as structured genomic coordinates.
Audit Metadata