Versioned security assessment

Report ID: SA-A25199BC

7/5/2026, 6:46:12 PM

clinical-reports security assessment v6

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
clinical-reports
Version
v6
Maintainer
K-Dense-AI
Coverage
31 Files scanned · 11,881 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

High

2 confirmed security findings require attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Most static findings are false positives caused by clinical terminology, Markdown backticks, and expected local report-output scripts. No evidence found of command injection, credential access, network calls, or hidden data exfiltration in the reviewed code. Two semantic risks remain: an included self-audit that claims safety and a mandatory external AI figure workflow that could expose clinical data.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

31 Files scanned · 11,881 Lines analyzed

2 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Observed in 5 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 43 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (2)

RISK-001 High
Prompt Injection Attempt Detected
evaluation_output.json claims "no security concerns" and says "all static findings are false positives." This untrusted self-audit can bias automated reviewers and should not ship with the skill.
The file contains a direct safety claim about the package rather than operational code. It may be leftover evaluation output, but it is still untrusted content that can influence review.
RISK-002 High
External AI Figure Workflow May Expose Clinical Data
SKILL.md mandates an AI-generated figure for every clinical report and directs users to a scientific-schematics workflow. Clinical report figure prompts may include patient timelines or trial data, creating a privacy exposure risk if not de-identified.
The text explicitly makes external AI figure generation mandatory and gives a workflow for clinical report diagrams. The privacy risk is inferred from the clinical-report domain and the referenced patient timelines.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Untrusted self-audit content is included in the package.
    Remove evaluation_output.json or replace it with neutral test artifacts that do not claim audit approval or safety status.
  2. FIX-002
    High
    External AI figure generation is mandatory for clinical reports.
    Make figure generation optional and require de-identified prompts before using scientific-schematics or any external image workflow.
  3. FIX-003
    Medium
    Local scripts write to user-supplied output paths.
    Add overwrite confirmation, path normalization, and clear output-directory guidance for all scripts that create files.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable