clinical-reports

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection attack surface as it is designed to ingest and process untrusted clinical data provided by users.
  • Ingestion points: Clinical report files are read by the agent through the Bash tool to perform validation and data extraction via Python scripts such as validate_case_report.py, extract_clinical_data.py, and check_deidentification.py.
  • Boundary markers: The instructions in SKILL.md do not provide explicit delimiters or instructions to treat the ingested clinical data as untrusted text rather than agent instructions.
  • Capability inventory: The skill has access to Read, Write, Edit, and Bash tools, which could be leveraged if an ingested report contains adversarial instructions that the agent follows.
  • Sanitization: The Python validation scripts use regular expressions to match specific patterns (vitals, identifiers, headings) but do not sanitize the text for prompt injection patterns.
  • [SAFE]: The skill provides numerous reference documents and templates that adhere to established medical standards (CARE, ICH-E3, HIPAA, CONSORT) and utilize well-known medical terminology (ICD-10, SNOMED-CT, LOINC).
  • [SAFE]: All external URL references are directed toward trusted medical organizations and regulatory bodies (e.g., hhs.gov, ich.org, care-statement.org) for documentation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 11:14 AM
Security Audit — agent-trust-hub — clinical-reports