openevidence-prod-checklist

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No security threats or malicious patterns were identified. The skill adheres to security best practices by providing specific instructions to protect credentials and sensitive clinical data, and by limiting network activity to official documentation sites through the WebFetch tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests user-supplied workflow descriptions and fetches external documentation. The ingestion points include the workflow argument and external OpenEvidence pages via WebFetch. Boundary markers are present in the form of instructions to separate facts from assumptions and leave consequential decisions to accountable owners. The skill's capabilities include Write, Edit, and WebFetch tools. Sanitization is addressed through explicit instructions to redact patient identifiers and credential data before output. The risk is assessed as safe due to the restrictive and safety-focused nature of the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 PM
Security Audit — agent-trust-hub — openevidence-prod-checklist