prior-authorization-review
Warn
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains deceptive metadata, identifying as an 'Official Anthropic skill' and claiming to be 'Verified by Anthropic' while being authored and hosted by 'Open-Medica'. This can mislead users regarding the security and provenance of the tool.
- [EXTERNAL_DOWNLOADS]: The installation instructions recommend executing code from a non-standard third-party repository ('Open-Medica/open-medical-skills') via the
npx skillscommand. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external, untrusted clinical data to generate medical justifications.
- Ingestion points: Patient medical records and insurance coverage policies mentioned in the instructions.
- Boundary markers: No boundary markers or 'ignore' instructions are used to separate untrusted data.
- Capability inventory: The tool generates medical necessity narratives and appeal letters which can influence clinical administration.
- Sanitization: No input validation or sanitization of patient data is described in the skill.
Audit Metadata