openevidence-core-workflow-a
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation and code examples for clinical decision support via the OpenEvidence API. The domains and resources referenced (openevidence.com) are legitimate and consistent with the healthcare context of the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests data from external clinical literature and guideline databases, creating a potential attack surface.
- Ingestion points: API responses from clinical searches and drug interaction checks as described in
SKILL.md. - Boundary markers: No explicit delimiters or instructions are provided in the documentation to isolate retrieved clinical data from agent instructions.
- Capability inventory: The skill is configured to allow
Read,Write,Edit,Grep, andBash(npm:*)tools. - Sanitization: The instructions do not specify validation or sanitization requirements for the content returned by the OpenEvidence API.
Audit Metadata