NYC

opentargets-database

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOWPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill is designed to ingest and process data from the Open Targets Platform API (api.platform.opentargets.org). This creates an inherent surface for indirect prompt injection if the external data sources (such as text-mined biomedical literature or public clinical notes) contain adversarial instructions. Evidence Chain: 1. Ingestion points: GraphQL API responses in api_reference.md. 2. Boundary markers: Absent in provided documentation snippets. 3. Capability inventory: Retrieval of target, disease, and drug annotations for reasoning. 4. Sanitization: No sanitization or validation is demonstrated in the code examples.
  • [EXTERNAL_DOWNLOADS] (INFO): The Python code snippets demonstrate the use of the requests library to fetch data from a public scientific API. This is standard behavior for the stated purpose of the skill.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 11:27 PM