tooluniverse-binder-discovery

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a legitimate scientific research workflow for drug discovery, utilizing a comprehensive suite of domain-specific tools.
  • [DATA_EXPOSURE_EXFILTRATION]: The skill interacts with the NVIDIA_API_KEY environment variable to enable integration with NVIDIA NIM services. This is a standard and safe method for providing necessary credentials to external ML services within this platform's context. No unauthorized exfiltration of this or any other data was detected.
  • [EXTERNAL_DOWNLOADS]: The workflow involves fetching scientific data from reputable and well-known organizations including the European Bioinformatics Institute (ChEMBL, UniProt, PDB), the National Center for Biotechnology Information (PubChem, PubMed), and NVIDIA. These external references are restricted to retrieving biological and chemical data required for the discovery process.
  • [COMMAND_EXECUTION]: The skill does not attempt to execute arbitrary shell commands or escalate system privileges. Its file system operations are limited to generating markdown reports and CSV data files containing research results.
  • [PROMPT_INJECTION]: There are no instructions that attempt to bypass safety filters, override core agent behavior, or reveal system prompts. The provided guidelines are strictly focused on operationalizing the binder discovery workflow.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes data from external sources such as PubMed and bioRxiv, this presents a typical surface for indirect prompt injection common to any tool that summarizes web content. However, the risk is assessed as low given the scientific context and lack of exploitable administrative capabilities within the skill's defined scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 11:36 PM