fda-consultant-specialist
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The instructions and code within the skill do not exhibit any malicious patterns, such as credential theft, unauthorized remote execution, or command injection. The content is primarily educational and regulatory in nature.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external clinical data (PHI) and regulatory submissions, which constitutes an ingestion point for untrusted data. While this establishes a potential surface for indirect prompt injection, no exploitable logic exists in the provided placeholders.
- Ingestion points: PHI data flow analysis and clinical investigation evaluations described in SKILL.md.
- Boundary markers: None; there are no delimiters or instructions to ignore embedded commands within the data being analyzed.
- Capability inventory: Mentions scripts for tracking FDA submissions and checking QSR compliance.
- Sanitization: None present in the placeholder script provided.- [METADATA_POISONING]: The SKILL.md file references a specific suite of tools (e.g., fda-submission-tracker.py, qsr-compliance-checker.py) and reference documents that are missing from the skill bundle. The bundle contains only generic example files, resulting in an inconsistency between the skill's stated resources and its actual implementation.
Audit Metadata