openevidence-migration-deep-dive

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes legacy prompts and reports, which serves as an ingestion surface for potentially untrusted data that could influence the agent's behavior. \n
  • Ingestion points: Instructions in SKILL.md direct the agent to inventory legacy Deep Consult prompts, reports, and user groups. \n
  • Boundary markers: The instructions do not define specific syntax delimiters for the content being processed, but provide high-level conceptual boundaries. \n
  • Capability inventory: The skill has access to Read, Glob, Grep, Write, Edit, and WebFetch tools across its scripts. \n
  • Sanitization: The skill includes mandatory instructions to redact patient and credential data, use synthetic data for testing, and avoid reusing legacy prompts containing PHI.\n- [EXTERNAL_DOWNLOADS]: The skill is configured to fetch current documentation from the official OpenEvidence domain. \n
  • Evidence: Instructions in SKILL.md limit WebFetch usage specifically to current first-party OpenEvidence documentation. \n
  • Sources: Fetches resources from openevidence.com and trust.openevidence.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 PM
Security Audit — agent-trust-hub — openevidence-migration-deep-dive