pp-clinical-trials
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install the
clinical-trials-pp-cliandclinical-trials-pp-mcptools from the official infrastructure of the vendor (mvanhorn) via NPM (@mvanhorn/printing-press-library) and GitHub (github.com/mvanhorn/printing-press-library).\n- [COMMAND_EXECUTION]: The skill uses theBashtool to execute theclinical-trials-pp-clibinary for functions such as searching clinical trials, performing drug comparisons, and generating markdown research reports.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external public registries like ClinicalTrials.gov and EU CTIS. \n - Ingestion points: Data enters the agent context via the
search,studies list, andfetch-studycommands.\n - Boundary markers: Explicit delimiters are not provided in the prompt instructions.\n
- Capability inventory: The agent can execute commands through the
Bashtool to interact with the clinical trials CLI.\n - Sanitization: The CLI normalization and deduplication layer acts as a filter for the raw registry data before it is presented to the agent.\n- [DATA_EXFILTRATION]: The CLI includes a built-in
--deliver webhook:<url>feature that allows tool outputs to be POSTed to a specified endpoint. This is a documented functionality for integration and automation and is standard for this tool's capabilities.
Audit Metadata