clinical-decision-support-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides explicit instructions and shell command patterns for the agent to execute local Python scripts located in the scripts/ directory. These include tools for generating scientific schematics (generate_schematic.py), survival analysis (generate_survival_analysis.py), and statistical calculations (calculate_statistics.py). This is a legitimate functional requirement for its stated clinical reporting purpose.
  • [PROMPT_INJECTION]: The accompanying SAFETY.md file contains detailed examples of adversarial prompt injections (e.g., authority claims, social engineering to bypass disclosures) used as test cases to document and verify the effectiveness of the skill's safety guardrails. These are presented as educational/safety data and do not represent a vulnerability in the skill itself.
  • [DATA_EXFILTRATION]: The skill is specifically designed to handle sensitive clinical and pharmaceutical data. While this represents a high-value data surface, the skill includes explicit requirements for HIPAA de-identification, confidentiality headers, and conflict-of-interest disclosures to ensure regulatory compliance. No network exfiltration commands were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:30 PM
Security Audit — agent-trust-hub — clinical-decision-support-hardened