terra-lab-reports
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external, untrusted content (clinical lab reports in PDF and image formats) which are processed via the Terra Lab Reports API. Ingestion points: Files are uploaded to the
/v2/lab-reportsendpoint. Boundary markers: The skill does not define specific prompt delimiters or instructions to ignore embedded content within the processed files. Capability inventory: Integrations based on this skill typically involve reading files, performing network requests to the Terra API, and processing the resulting structured data. Sanitization: While the skill provides rules for handling matched/unmatched biomarkers and reference ranges, it does not explicitly address the sanitization of extracted text for potential injection attacks. - [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing the vendor's command-line interface tools through official repositories (
tryterra/tap/terravia Homebrew and@tryterra/clivia NPM).
Audit Metadata