tooluniverse-immunotherapy-response-prediction

Pass

Audited by Gen Agent Trust Hub on Mar 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: No evidence of direct prompt injection or bypass attempts was found. Instructions are strictly focused on medical data analysis and reporting.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it retrieves and processes content from external, potentially untrusted sources like PubMed abstracts and clinical trial descriptions.
  • Ingestion points: Data retrieved from tools such as PubMed_search_articles and clinical_trials_search are incorporated into the agent's context in SKILL.md (Phase 8).
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the retrieved text.
  • Capability inventory: The skill primarily performs data retrieval and processing; it does not contain capabilities for arbitrary command execution or system modification.
  • Sanitization: The skill does not describe specific sanitization steps for text retrieved from external databases before it is used to generate the clinical report.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with numerous well-known technology and scientific services including OpenTargets (EBI/Sanger), Ensembl (EBI), MyGene (Scripps Research), and US Government databases (FDA, ClinicalTrials.gov). These are recognized as trusted sources for medical and genomic data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 8, 2026, 01:17 PM