hipaa-compliance-checker

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill contains installation instructions referencing the author's official GitHub repository (Open-Medica/open-medical-skills) via the command npx skills add. This represents a standard deployment mechanism for the vendor's resources.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as its primary purpose is to ingest and process untrusted clinical data.
  • Ingestion points: Individual clinical notes or document collections (described in SKILL.md).
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the processing examples.
  • Capability inventory: Performs entity extraction, masking, and synthetic data replacement (obfuscation) across clinical text.
  • Sanitization: No input sanitization or validation of the clinical text is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 01:03 PM
Security Audit — agent-trust-hub — hipaa-compliance-checker