terra-lab-reports

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external, untrusted content (clinical lab reports in PDF and image formats) which are processed via the Terra Lab Reports API. Ingestion points: Files are uploaded to the /v2/lab-reports endpoint. Boundary markers: The skill does not define specific prompt delimiters or instructions to ignore embedded content within the processed files. Capability inventory: Integrations based on this skill typically involve reading files, performing network requests to the Terra API, and processing the resulting structured data. Sanitization: While the skill provides rules for handling matched/unmatched biomarkers and reference ranges, it does not explicitly address the sanitization of extracted text for potential injection attacks.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing the vendor's command-line interface tools through official repositories (tryterra/tap/terra via Homebrew and @tryterra/cli via NPM).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 09:04 AM
Security Audit — agent-trust-hub — terra-lab-reports