pydicom
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes local DICOM files, which are untrusted external data sources that could contain malicious instructions. Ingestion points: DICOM datasets are ingested via
pydicom.dcmreadacross all helper scripts, includingscripts/extract_metadata.pyandscripts/anonymize_dicom.py. Boundary markers: The skill includes a 'Mandatory safety boundary' and 'Agent operating procedure' inSKILL.mdthat explicitly prohibit printing full datasets, require allowlists for metadata, and mandate human review for clinical outputs. Capability inventory: The skill is limited to local file read/write operations, image rendering using Pillow, and pseudonymization. It contains no network access tools or arbitrary command execution capabilities. Sanitization: Scripts utilize strict allowlists for metadata extraction and recursive tag removal/pseudonymization to prevent data leakage and unintentional instruction processing. - [SAFE]: The skill implements significant technical controls for secure local execution. Path Validation:
scripts/_common.pyemployschecked_inputandchecked_outputto sanitize file paths, preventing directory traversal and restricting access to a defined local root. Atomic Operations: File writes are performed using atomic methods inscripts/_common.pyto ensure data integrity and prevent symlink-based attacks. Credential Safety: The pseudonymization tool inscripts/anonymize_dicom.pyenforces strict file permissions (0600) and ownership checks for local key files.
Audit Metadata