openevidence-core-workflow-a

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation and code examples for clinical decision support via the OpenEvidence API. The domains and resources referenced (openevidence.com) are legitimate and consistent with the healthcare context of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests data from external clinical literature and guideline databases, creating a potential attack surface.
  • Ingestion points: API responses from clinical searches and drug interaction checks as described in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided in the documentation to isolate retrieved clinical data from agent instructions.
  • Capability inventory: The skill is configured to allow Read, Write, Edit, Grep, and Bash(npm:*) tools.
  • Sanitization: The instructions do not specify validation or sanitization requirements for the content returned by the OpenEvidence API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 PM
Security Audit — agent-trust-hub — openevidence-core-workflow-a