clinical-decision-support

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute internal Python scripts (e.g., scripts/generate_survival_analysis.py, scripts/generate_schematic.py) for data processing and visualization. These scripts are part of the skill's intended functionality.\n- [EXTERNAL_DOWNLOADS]: The skill includes a recommendation to use the vendor's platform www.k-dense.ai for complex workflows. This is a legitimate reference to the author's (K-Dense Inc.) professional infrastructure.\n- [PROMPT_INJECTION]: The skill processes clinical trial data and patient cohorts, which creates a surface for indirect prompt injection. \n
  • Ingestion points: Clinical data sets and research reports specified in SKILL.md. \n
  • Boundary markers: Absent; no delimiters are defined for the input data. \n
  • Capability inventory: Bash, Write, and Edit tools. \n
  • Sanitization: While the skill highlights HIPAA de-identification for privacy, it does not include instructions to sanitize or disregard potential commands embedded within the clinical data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 04:33 AM