digital-health-clinical-asr-build

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with Merriam-Webster (dictionaryapi.com) and NVIDIA Cloud Functions (grpc.nvcf.nvidia.com) to perform phonetic lookups and audio synthesis. These are well-known or vendor-owned services integral to the skill's documented workflow.\n- [DATA_EXFILTRATION]: User-provided clinical terms and generated sentences are sent to external APIs. This data transfer is prominently disclosed to the user with specific warnings to avoid Protected Health Information (PHI) and to verify organizational data governance policies.\n- [COMMAND_EXECUTION]: The skill includes technical documentation and Bash snippets for performing local schema and file integrity validations. These scripts run standard Python checks on the skill's own generated output files.\n- [CREDENTIALS_UNSAFE]: Guidelines for managing API keys (NVIDIA_API_KEY and DICTIONARY_API_KEY) are provided, emphasizing secure storage in environment variables or secret managers. No hardcoded credentials or secrets were found in the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 07:42 PM
Security Audit — agent-trust-hub — digital-health-clinical-asr-build