imaging-data-commons

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to official NCI services at api.imaging.datacommons.cancer.gov and proxy.imaging.datacommons.cancer.gov. It also uses urllib.request to fetch version information from pypi.org and api.github.com (trusted registries). Imaging data is downloaded from public AWS S3 (s3.amazonaws.com) and Google Cloud Storage (storage.googleapis.com) buckets, which are standard for the host platform's scientific data partnerships.
  • [COMMAND_EXECUTION]: The skill includes a helper script (scripts/check_version.py) to verify the environment. It recommends standard package installation commands for idc-index via pip or uv. These are routine configuration tasks for the intended scientific analysis use case.
  • [DYNAMIC_EXECUTION]: Utilizes duckdb for relational metadata queries and generates standard Python analysis blocks using the idc-index library. These operations are consistent with the skill's primary purpose of database discovery and data handling.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes extensive imaging and clinical metadata from NCI's public repositories. While this constitutes an external data ingestion surface, it is necessary for the skill's operation.
  • Ingestion points: NCI REST API responses, local DuckDB Parquet indices, and cloud storage metadata files.
  • Boundary markers: No explicit delimiters are used in the provided reference scripts to separate data from instructions.
  • Capability inventory: File system write access (for downloads), network API access, and SQL execution capabilities.
  • Sanitization: The skill relies on standard scientific libraries (pandas, duckdb, pydicom) which provide typical data handling protections.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — imaging-data-commons