openevidence-observability

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a monitoring framework for clinical queries, which could be exploited if malicious instructions are embedded within the queries being observed by the agent.
  • Ingestion points: The skill monitors clinical queries via the trackClinicalQuery instrumentation defined in SKILL.md.
  • Boundary markers: The instructions include clear warnings to avoid logging patient identifiers or query text to maintain HIPAA compliance, serving as a data boundary.
  • Capability inventory: The skill configuration allows for Read, Write, Edit, and Grep tools, which could be leveraged if an injection is successful.
  • Sanitization: The references/implementation.md file specifies the use of pino logger redaction for sensitive fields such as patientId, mrn, and ssn.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 PM
Security Audit — agent-trust-hub — openevidence-observability