pp-clinical-trials

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the clinical-trials-pp-cli and clinical-trials-pp-mcp tools from the official infrastructure of the vendor (mvanhorn) via NPM (@mvanhorn/printing-press-library) and GitHub (github.com/mvanhorn/printing-press-library).\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute the clinical-trials-pp-cli binary for functions such as searching clinical trials, performing drug comparisons, and generating markdown research reports.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external public registries like ClinicalTrials.gov and EU CTIS. \n
  • Ingestion points: Data enters the agent context via the search, studies list, and fetch-study commands.\n
  • Boundary markers: Explicit delimiters are not provided in the prompt instructions.\n
  • Capability inventory: The agent can execute commands through the Bash tool to interact with the clinical trials CLI.\n
  • Sanitization: The CLI normalization and deduplication layer acts as a filter for the raw registry data before it is presented to the agent.\n- [DATA_EXFILTRATION]: The CLI includes a built-in --deliver webhook:<url> feature that allows tool outputs to be POSTed to a specified endpoint. This is a documented functionality for integration and automation and is standard for this tool's capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 12:11 AM
Security Audit — agent-trust-hub — pp-clinical-trials