tooluniverse-data-integration-analysis
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill explicitly directs the agent to write and execute Python code via Bash to perform calculations, statistical modeling, and data visualization using libraries like pandas and scipy. This behavior is the primary intended function for scientific data analysis.- [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection as it processes data from external sources like PubMed and biological databases. Evidence Chain: 1. Ingestion points: External biological databases (PubMed, KEGG, STRING, etc.). 2. Boundary markers: Absent. 3. Capability inventory: Python execution via Bash and ToolUniverse tool access. 4. Sanitization: None mentioned, but the focus is on structured evidence grading which inherently provides a layer of validation.- [SAFE]: No obfuscation, hardcoded credentials, or persistence mechanisms were found. All external references are to well-known scientific databases and repositories consistent with the skill's purpose.
Audit Metadata