hipaa-compliance
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-generated content such as journals and chat logs, serving as a potential vector for indirect prompt injection. 1. Ingestion points: The skill explicitly identifies and processes untrusted inputs including 'Journal entries', 'Chat conversations', and 'Check-in mood/cravings'. 2. Boundary markers: The instructions and provided code patterns do not implement explicit delimiters or boundary markers to isolate user-provided content from agent instructions. 3. Capability inventory: The skill environment allows 'Read', 'Write', and 'Edit' tools, which could be leveraged if the agent inadvertently follows instructions embedded within the health data. 4. Sanitization: While the skill details rigorous sanitization for outgoing audit logs, it lacks specific validation or sanitization routines for the data prior to its consumption by the AI agent prompt context.
Audit Metadata