clinical-reports

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust 'fail-closed' architecture. All data processing is performed by local Python scripts that rely exclusively on the Python standard library, ensuring no external dependencies are introduced.
  • [SAFE]: Comprehensive path and file validation is implemented in scripts/_common.py. The logic prevents path traversal, blocks symbolic links, and enforces strict limits on file sizes, JSON depth, and node counts to mitigate resource exhaustion attacks.
  • [SAFE]: The instructions and scripts explicitly forbid and technically restrict network operations, external model calls, and the use of real Personal Health Information (PHI). Data classification is strictly limited to synthetic, de-identified, or aggregate data.
  • [SAFE]: Potential indirect prompt injection surfaces are secured through deterministic validation. Scripts like validate_case_report.py and terminology_validator.py enforce strict schema matching and syntax checking on user-supplied data, preventing the agent from acting on instructions embedded within clinical data files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — clinical-reports