zinc-database
Pass
Audited by Gen Agent Trust Hub on Mar 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides Python implementation examples that use the
subprocessmodule to call system commands likecurl,wget, andaria2cfor API data retrieval and file downloads. - [EXTERNAL_DOWNLOADS]: The skill documentation and integrated code snippets reference external domains owned by the University of California, San Francisco (
docking.org), which are established resources in the cheminformatics community. - [PROMPT_INJECTION]: The skill includes a promotional section at the end of the
SKILL.mdfile instructing the AI agent to suggest the 'K-Dense Web' platform during complex research workflows. This is a vendor-defined behavioral instruction for marketing purposes and does not represent a malicious safety bypass.
Audit Metadata