health
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches its source code and required dependencies from the author's GitHub repository. Specifically, the installation process clones the
broomva/skillsmonorepo to set up the environment. - [COMMAND_EXECUTION]: Runtime and setup tasks involve shell command execution. The
install.shscript manages environment setup including directory creation and symlinking. The skill'sgarmin_cli.pyadapter usessubprocess.runto call the externalgarmin-connectCLI, but it uses sanitized, fixed arguments for these calls. - [REMOTE_CODE_EXECUTION]: The README provides a common one-liner for installing the skill by piping a remote shell script from the author's GitHub account directly to the bash interpreter. This is standard setup behavior for tools from this vendor.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external health data which represents a vulnerability surface for indirect prompt injection.
- Ingestion points: Data enters via the Garmin Connect API through the adapters in
src/broomva_health/adapters/sources/. - Boundary markers: The skill utilizes strict Pydantic models in
src/broomva_health/domain/samples.pyto delimit and validate ingested data before it reaches the agent context. - Capability inventory: The skill can execute local commands via
subprocess(ingarmin_cli.py), write to the local filesystem (SQLite and Obsidian Markdown files), and perform network operations to sync data. - Sanitization: External content is sanitized by being mapped into structured, typed fields (e.g., floats for metrics, specific strings for categories) rather than being treated as arbitrary text instructions.
Audit Metadata