pydicom

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local DICOM files, which are untrusted external data sources that could contain malicious instructions. Ingestion points: DICOM datasets are ingested via pydicom.dcmread across all helper scripts, including scripts/extract_metadata.py and scripts/anonymize_dicom.py. Boundary markers: The skill includes a 'Mandatory safety boundary' and 'Agent operating procedure' in SKILL.md that explicitly prohibit printing full datasets, require allowlists for metadata, and mandate human review for clinical outputs. Capability inventory: The skill is limited to local file read/write operations, image rendering using Pillow, and pseudonymization. It contains no network access tools or arbitrary command execution capabilities. Sanitization: Scripts utilize strict allowlists for metadata extraction and recursive tag removal/pseudonymization to prevent data leakage and unintentional instruction processing.
  • [SAFE]: The skill implements significant technical controls for secure local execution. Path Validation: scripts/_common.py employs checked_input and checked_output to sanitize file paths, preventing directory traversal and restricting access to a defined local root. Atomic Operations: File writes are performed using atomic methods in scripts/_common.py to ensure data integrity and prevent symlink-based attacks. Credential Safety: The pseudonymization tool in scripts/anonymize_dicom.py enforces strict file permissions (0600) and ownership checks for local key files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pydicom