omero-integration

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION] (LOW): Indirect Prompt Injection Surface. The skill ingests untrusted metadata and table data from external OMERO servers. Evidence Chain: (1) Ingestion points: Data retrieved via BlitzGateway. (2) Boundary markers: Absent. (3) Capability inventory: Data management and pixel analysis. (4) Sanitization: Absent.
  • [COMMAND_EXECUTION] (LOW): The skill facilitates the creation and execution of server-side scripts (OMERO.scripts) for automation. This provides a dynamic code execution surface on the connected server, though it is a primary feature of the platform.
  • [EXTERNAL_DOWNLOADS] (LOW): The skill suggests installing 'omero-py' via pip or conda without version pinning. While a standard scientific library, it is not on the pre-approved trusted sources list.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:08 PM