pyhealth

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process clinical Electronic Health Record (EHR) data from various sources such as MIMIC and eICU. While this represents a data ingestion surface, the skill includes explicit safety protocols requiring the agent to verify de-identification status and patient data permissions before processing. Ingestion points include the dataset loader classes in SKILL.md and references/datasets.md. The capability inventory is limited to standard model training and evaluation using the Trainer class, with procedural sanitization performed through agent-led verification of data privacy standards.
  • [EXTERNAL_DOWNLOADS]: The skill fetches synthetic clinical datasets from a well-known cloud storage provider to allow for demos and testing without requiring sensitive credentials. These downloads are directed to documented, public research-oriented buckets specifically provided for the PyHealth library.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pyhealth