hedis-nlp
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior or security risks were identified in the analyzed files. The skill adheres to best practices for clinical NLP engineering.
- [PROMPT_INJECTION]: The skill's instructions in
SKILL.mdinclude a mandatory 'Safety & Compliance Gate' that must be run first, which reinforces safety guidelines rather than attempting to bypass them. - [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data exfiltration. The skill contains explicit instructions to prevent the output of PHI and requires confirmation of HIPAA-compliant environments.
- [EXTERNAL_DOWNLOADS]: The skill references several well-known and reputable clinical NLP libraries (such as medspaCy and Apache cTAKES) as recommendations for implementation, which is appropriate for its stated purpose.
- [COMMAND_EXECUTION]: No unauthorized or dangerous shell command execution was found. The installation command provided in the README is standard for this ecosystem.
Audit Metadata