tooluniverse-immunotherapy-response-prediction
Pass
Audited by Gen Agent Trust Hub on Mar 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: No evidence of direct prompt injection or bypass attempts was found. Instructions are strictly focused on medical data analysis and reporting.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it retrieves and processes content from external, potentially untrusted sources like PubMed abstracts and clinical trial descriptions.
- Ingestion points: Data retrieved from tools such as
PubMed_search_articlesandclinical_trials_searchare incorporated into the agent's context inSKILL.md(Phase 8). - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the retrieved text.
- Capability inventory: The skill primarily performs data retrieval and processing; it does not contain capabilities for arbitrary command execution or system modification.
- Sanitization: The skill does not describe specific sanitization steps for text retrieved from external databases before it is used to generate the clinical report.
- [EXTERNAL_DOWNLOADS]: The skill interacts with numerous well-known technology and scientific services including OpenTargets (EBI/Sanger), Ensembl (EBI), MyGene (Scripps Research), and US Government databases (FDA, ClinicalTrials.gov). These are recognized as trusted sources for medical and genomic data.
Audit Metadata