tooluniverse-immunotherapy-response-prediction

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Detailed analysis of the skill's instructions confirms it is designed for medical decision support without any malicious intent or security vulnerabilities.- [EXTERNAL_DOWNLOADS]: The skill interfaces with legitimate medical data providers including OpenTargets, PubMed, and FDA databases. These references are appropriate for the skill's stated purpose of clinical evidence retrieval.- [PROMPT_INJECTION]: Instructions prioritize structured analysis and evidence grading; no bypass or override techniques are present.- [DATA_EXFILTRATION]: No sensitive local information is accessed, and data retrieval is limited to public medical databases.- [COMMAND_EXECUTION]: The skill defines a set of tool calls for data retrieval but does not execute arbitrary shell commands or system-level processes.- [REMOTE_CODE_EXECUTION]: No remote code execution or dynamic code evaluation patterns were found.- [SAFE]: Mandatory Evidence Chain for Category 8 (Indirect Prompt Injection) surface analysis: 1. Ingestion points: Patient tumor profile data (cancer type, mutations, biomarkers) provided via user prompts; 2. Boundary markers: The skill instructs the agent to parse mutations into a structured format, which acts as an implicit boundary; 3. Capability inventory: Tool calls to medical APIs and file-writing for the final report; 4. Sanitization: No explicit sanitization or escaping of user input is mentioned, but the analysis workflow is highly structured which reduces the impact of potential malicious inputs. This surface is standard for data-processing skills and does not represent a specific vulnerability.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 04:32 AM