tracking-taxonomy-updates
Pass
Audited by Gen Agent Trust Hub on Feb 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS] (LOW): The skill setup involves downloading bioinformatics packages such as
gtdbtk,eukcc, andtaxonkitfrom thebiocondaandconda-forgechannels via the Pixi package manager. Additionally, it pulls thebryce911/bbtoolsDocker image. These dependencies are standard in scientific research but are hosted on external third-party platforms. - [COMMAND_EXECUTION] (LOW): The skill provides pre-defined tasks for executing bioinformatics tools within the configured environment. These commands are tailored to the skill's primary function and are not designed for arbitrary system access.
- [INDIRECT_PROMPT_INJECTION] (LOW): The skill processes taxonomy data from external websites, creating a surface for potential instruction injection via data. 1. Ingestion points: External release notes and authority web pages from NCBI, GTDB, and ICTV. 2. Boundary markers: None present in the provided instructions. 3. Capability inventory: Execution of bioinformatics tools and local file management. 4. Sanitization: Not specified; content is summarized directly for reporting.
Audit Metadata