skills/broomva/skills/health/Gen Agent Trust Hub

health

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches its source code and required dependencies from the author's GitHub repository. Specifically, the installation process clones the broomva/skills monorepo to set up the environment.
  • [COMMAND_EXECUTION]: Runtime and setup tasks involve shell command execution. The install.sh script manages environment setup including directory creation and symlinking. The skill's garmin_cli.py adapter uses subprocess.run to call the external garmin-connect CLI, but it uses sanitized, fixed arguments for these calls.
  • [REMOTE_CODE_EXECUTION]: The README provides a common one-liner for installing the skill by piping a remote shell script from the author's GitHub account directly to the bash interpreter. This is standard setup behavior for tools from this vendor.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external health data which represents a vulnerability surface for indirect prompt injection.
  • Ingestion points: Data enters via the Garmin Connect API through the adapters in src/broomva_health/adapters/sources/.
  • Boundary markers: The skill utilizes strict Pydantic models in src/broomva_health/domain/samples.py to delimit and validate ingested data before it reaches the agent context.
  • Capability inventory: The skill can execute local commands via subprocess (in garmin_cli.py), write to the local filesystem (SQLite and Obsidian Markdown files), and perform network operations to sync data.
  • Sanitization: External content is sanitized by being mapped into structured, typed fields (e.g., floats for metrics, specific strings for categories) rather than being treated as arbitrary text instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:27 PM
Security Audit — agent-trust-hub — health