discharge

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data in the form of medical images and text descriptions provided by the user.
  • Ingestion points: The skill accepts input via text descriptions and file paths to images (e.g., @medical-reports/discharge-summary.jpg) as defined in the argument-hint and Source Type Recognition sections of SKILL.md.
  • Boundary markers: While a structured prompt template is provided for the image analysis tool, there are no specific instructions or delimiters to ensure the agent ignores potentially malicious or adversarial instructions embedded within the medical documents themselves.
  • Capability inventory: The skill utilizes the Read tool to access local files, the Write tool to save JSON data to the data/ directory, and invokes an image analysis tool (mcp__4_5v_mcp__analyze_image) to process the records.
  • Sanitization: No evidence of sanitization, validation, or escaping of the extracted medical data (such as drug names, dosages, or discharge orders) is present before the data is written to the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:08 PM
Security Audit — agent-trust-hub — discharge