fraud-detection
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- Automated Data Processing: The skill employs system tools like DuckDB and Node.js for high-performance claim analysis. These command executions are confined to the skill's managed data environment and include path validation measures for the output directory.
- Reference Data Acquisition: The skill references public datasets from established government domains, including
cms.gov,oig.hhs.gov, andnlm.nih.gov. These downloads are necessary for the skill's function and originate from verified authorities to provide policy context for deterministic screening. - Large Language Model Integration: The skill uses model-assisted stages for narrative synthesis and adjudication. To manage the risk of indirect prompt injection from processed claim data, the skill uses explicit directives instructing the model to treat input as non-executable data and implements a deterministic floor that verifies all financial figures.
- Application Hardening: Security-conscious patterns are visible in the implementation, such as the use of formula injection protection for spreadsheet exports and single-pass HTML escaping for rendered provider dashboards.
Audit Metadata