healthtech-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides domain-specific knowledge and standard Python implementation examples for clinical workflows. It correctly emphasizes HIPAA compliance and best practices for data security.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process sensitive patient data (Medical Record Numbers, vitals, medications). While the included Python code is a mock implementation for demonstration, the intended use involves ingesting potentially untrusted data. The execution environment includes powerful tools like
BashandWebSearch. No specific input sanitization or boundary markers are defined in the instructions for handling clinical data that might contain malicious text, although this is inherent to the healthtech domain and the skill does not exhibit active exploitation surfaces. - Ingestion points: Patient profiles and vital sign readings processed via the
RemotePatientMonitoringSystemclass. - Boundary markers: Not explicitly defined in instructions.
- Capability inventory:
Read,Write,Bash,WebSearchtools available to the agent. - Sanitization: Standard Python data structures are used, but no explicit LLM-specific sanitization of clinical text is provided.
Audit Metadata