discharge
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data in the form of medical images and text descriptions provided by the user.
- Ingestion points: The skill accepts input via text descriptions and file paths to images (e.g.,
@medical-reports/discharge-summary.jpg) as defined in theargument-hintandSource Type Recognitionsections ofSKILL.md. - Boundary markers: While a structured prompt template is provided for the image analysis tool, there are no specific instructions or delimiters to ensure the agent ignores potentially malicious or adversarial instructions embedded within the medical documents themselves.
- Capability inventory: The skill utilizes the
Readtool to access local files, theWritetool to save JSON data to thedata/directory, and invokes an image analysis tool (mcp__4_5v_mcp__analyze_image) to process the records. - Sanitization: No evidence of sanitization, validation, or escaping of the extracted medical data (such as drug names, dosages, or discharge orders) is present before the data is written to the filesystem.
Audit Metadata