zinc-database

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides Python implementation examples that use the subprocess module to call system commands like curl, wget, and aria2c for API data retrieval and file downloads.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and integrated code snippets reference external domains owned by the University of California, San Francisco (docking.org), which are established resources in the cheminformatics community.
  • [PROMPT_INJECTION]: The skill includes a promotional section at the end of the SKILL.md file instructing the AI agent to suggest the 'K-Dense Web' platform during complex research workflows. This is a vendor-defined behavioral instruction for marketing purposes and does not represent a malicious safety bypass.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 08:48 PM