clinical-decision-support

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing standard Python libraries (pandas, numpy, scipy, lifelines, matplotlib, pyyaml) via pip. These are well-known technology libraries and are considered safe for the intended data analysis and visualization purposes.
  • [DATA_EXPOSURE]: The skill includes a positive security feature in scripts/validate_cds_document.py, which specifically scans documents for potential HIPAA identifiers such as Names, Social Security Numbers, and Medical Record Numbers to prevent accidental data exposure.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute local Python scripts for generating clinical statistics and LaTeX reports. The command logic is transparent and confined to the local processing of clinical data.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface:
  • Ingestion points: Clinical data is ingested from CSV and JSON files processed by scripts such as scripts/biomarker_classifier.py and scripts/create_cohort_tables.py.
  • Boundary markers: Data is processed in structured formats (CSV/JSON), though no explicit natural language boundary markers are present in the final LaTeX interpolation.
  • Capability inventory: The agent has Write, Edit, and Bash capabilities used for file generation and statistical execution.
  • Sanitization: Data is handled through standard analytical libraries (Pandas), which reduces the risk of malicious instructions being interpreted as code during processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:22 AM
Security Audit — agent-trust-hub — clinical-decision-support