NYC

uniprot-database

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOWDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • Data Exposure & Exfiltration (LOW): The skill performs network requests to rest.uniprot.org. This domain is not on the trusted whitelist. While appropriate for the skill's purpose, it represents an external communication channel.\n- Indirect Prompt Injection (LOW): The skill retrieves data from an external API, creating a surface for indirect prompt injection.\n
  • Ingestion points: scripts/uniprot_client.py (via requests calls in search_proteins, get_protein, map_ids, and stream_results).\n
  • Boundary markers: Absent.\n
  • Capability inventory: scripts/uniprot_client.py contains only requests for data transfer; no subprocess, exec, eval, or file-write calls were detected.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 11:23 PM