imaging-data-commons

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python snippets that use subprocess.run to verify and upgrade the idc-index package via pip3. This logic is used solely for dependency management to ensure compatibility with specific data versions (e.g., v23). The command uses hardcoded arguments and does not incorporate unsanitized user input.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading medical imaging data (DICOM files) from public AWS S3 and Google Cloud Storage buckets. These buckets (idc-open-data, etc.) are official repositories managed by the NCI Imaging Data Commons and represent trusted research infrastructure.
  • [REMOTE_CODE_EXECUTION]: No instances of executing untrusted remote scripts (e.g., piping curl to bash) were found. The skill relies on well-known packages from the standard PyPI registry.
  • [DATA_EXFILTRATION]: No exfiltration patterns were detected. The skill's network activity is limited to querying public metadata indices and downloading scientific data to the user's local environment as intended.
  • [PROMPT_INJECTION]: The instructions focus on technical documentation and API usage patterns for data science. No attempts to bypass agent safety filters or override system behavior were detected.
  • [SAFE]: The skill follows security best practices by explicitly stating that no authentication is required for data access and providing clear instructions for using standard cloud authentication tools (like gcloud auth) only when necessary for advanced BigQuery features.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 03:10 AM