clinical-decision-support
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing standard Python libraries (
pandas,numpy,scipy,lifelines,matplotlib,pyyaml) viapip. These are well-known technology libraries and are considered safe for the intended data analysis and visualization purposes. - [DATA_EXPOSURE]: The skill includes a positive security feature in
scripts/validate_cds_document.py, which specifically scans documents for potential HIPAA identifiers such as Names, Social Security Numbers, and Medical Record Numbers to prevent accidental data exposure. - [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute local Python scripts for generating clinical statistics and LaTeX reports. The command logic is transparent and confined to the local processing of clinical data. - [PROMPT_INJECTION]: Indirect Prompt Injection Surface:
- Ingestion points: Clinical data is ingested from CSV and JSON files processed by scripts such as
scripts/biomarker_classifier.pyandscripts/create_cohort_tables.py. - Boundary markers: Data is processed in structured formats (CSV/JSON), though no explicit natural language boundary markers are present in the final LaTeX interpolation.
- Capability inventory: The agent has
Write,Edit, andBashcapabilities used for file generation and statistical execution. - Sanitization: Data is handled through standard analytical libraries (Pandas), which reduces the risk of malicious instructions being interpreted as code during processing.
Audit Metadata