tracking-taxonomy-updates

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The skill setup involves downloading bioinformatics packages such as gtdbtk, eukcc, and taxonkit from the bioconda and conda-forge channels via the Pixi package manager. Additionally, it pulls the bryce911/bbtools Docker image. These dependencies are standard in scientific research but are hosted on external third-party platforms.
  • [COMMAND_EXECUTION] (LOW): The skill provides pre-defined tasks for executing bioinformatics tools within the configured environment. These commands are tailored to the skill's primary function and are not designed for arbitrary system access.
  • [INDIRECT_PROMPT_INJECTION] (LOW): The skill processes taxonomy data from external websites, creating a surface for potential instruction injection via data. 1. Ingestion points: External release notes and authority web pages from NCBI, GTDB, and ICTV. 2. Boundary markers: None present in the provided instructions. 3. Capability inventory: Execution of bioinformatics tools and local file management. 4. Sanitization: Not specified; content is summarized directly for reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 05:19 PM