fhir-r4-implementation
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes a dedicated safety and compliance gate (Section 0) that explicitly instructs the agent to refuse real PHI and require version pinning for all standards. No instructions were found that attempt to bypass safety filters or override core agent behavior in a malicious way.
- [DATA_EXFILTRATION]: No patterns for accessing sensitive files (e.g., credentials, SSH keys) or exfiltrating data to external domains were identified. The skill is entirely composed of markdown-based guidance and templates.
- [EXTERNAL_DOWNLOADS]: The installation instructions utilize standard npx-based skill addition from a known platform. The references and templates point exclusively to authoritative HL7 and industry-standard documentation (e.g., hl7.org, cds-hooks.org, inferno.healthit.gov).
- [REMOTE_CODE_EXECUTION]: There is no executable code, script generation, or runtime compilation present in the skill files. All content consists of informational markdown and static JSON/FHIR templates.
Audit Metadata