openevidence-upgrade-migration

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates a vulnerability surface for indirect prompt injection through the processing of untrusted external data.
  • Ingestion points: The skill is configured to use WebFetch for retrieving first-party OpenEvidence documentation and Read for inspecting organizational policies and evidence (SKILL.md).
  • Boundary markers: The instructions explicitly mandate that the agent must "Separate documented facts from assumptions" and use a "stable rubric" for citations and uncertainty (SKILL.md).
  • Capability inventory: The skill possesses file system write access (Write, Edit) and network retrieval capabilities (WebFetch), as defined in the allowed-tools and instructions.
  • Sanitization: The instructions include robust sanitization requirements, specifically ordering the agent to "Redact patient and credential data" and "Never expose credentials, PHI, recordings, or unrestricted environment output" (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 PM
Security Audit — agent-trust-hub — openevidence-upgrade-migration