Medication Safety Advisor
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requirements and runtime instructions are consistent with a medication-safety lookup helper that calls public drug APIs and does not request unrelated credentials or install code.
This skill appears internally coherent, but it transmits drug names and allergy data to public APIs — do NOT include any patient identifiers (names, MRNs, DOB, addresses, notes that could re-identify a patient) in queries. For real patient data, only use this behind a HIPAA-compliant deployment and ensure a BAA is in place with any third-party API you rely on (and consider using payer/formulary APIs that support enterprise agreements). Treat the output as informational: the SKILL.md itself contains a clinical disclaimer — always have a licensed clinician/pharmacist verify before prescribing. If you plan to enable live formulary lookups, only supply FORMULARY_API_KEY with minimal required scopes and rotate keys per your security policy.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
