other
- Location
scripts/tox_agent.py:49- Finding
Risk Classification Ignores Documented QED and Veber Indicators
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tox_agent.py:49
Vulnerability Type:other: Unsafe risk-classification logic
Risk Level: MediumVulnerable Code
python 'risk': 'Low' if lipinski_viol == 0 and pains_count == 0 else 'Medium/High',Technical Analysis
The risk decision considers only Lipinski violations and PAINS matches. It does not consider the calculated QED score or Veber violations.
This behavior contradicts the documented classification in
SKILL.md, which states that:- A Low classification requires no Lipinski violations, no PAINS alerts, and QED greater than 0.5.
- Low QED should produce a Medium classification.
- Multiple Veber violations can produce a High classification.
- PAINS hits can produce a High classification.
The implementation can consequently label a compound as Low risk even when its QED is at or below 0.5 or it has multiple Veber violations. It also combines Medium and High into the non-specific value
Medium/High, rather than emitting the documented distinct classifications.These descriptor-based rules are drug-likeness heuristics rather than comprehensive toxicology predictions. Presenting their result as a general safety-risk classification may further encourage downstream consumers to place more confidence in the output than the underlying checks support.
Attack Path
- An attacker or upstream system supplies a syntactically valid SMILES value.
- The molecule is selected so it has no Lipinski violations and does not match either simplified PAINS pattern.
- The molecule nevertheless has a QED score at or below 0.5, one or more significant Veber violations, or both.
- The implementation calculates those indicators but omits them from the final risk decision.
- The result is returned with
"risk": "Low". - A downstream synthesis, screening, or derivative-selection component trusts the favorable classification and advances the co ...[truncated 1055 chars]
- Remediation
View remediation
Remediation Suggestions
Replace the binary expression with explicit, documented Low, Medium, and High classification rules. At minimum:
- Require all documented Low-risk conditions, including QED greater than 0.5 and acceptable Veber results.
- Return a distinct
MediumorHighvalue instead of the ambiguousMedium/Highvalue. - Define precedence when multiple indicators produce different classifications, with the most severe applicable classification taking priority.
- Add unit tests covering QED boundary values, each Lipinski threshold, PAINS hits, both Veber violations, and combinations of these conditions.
- Keep
SKILL.mdand the implementation synchronized through tests that validate the documented output contract. - Clearly label the result as heuristic drug-likeness and assay-interference screening, not a comprehensive toxicology determination.
- Require expert review and validated toxicology models before using the result to make safety-critical decisions.
