hrv-alexithymia-expert

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests physiological data and user-provided descriptions of physical sensations to identify emotional states and provide vocabulary training.
  • Ingestion points: Data enters the agent's context through parameters like rr_intervals and body_signals used in the detect_emotional_state and expand_emotional_vocabulary functions located in references/hrv-metrics.md and references/alexithymia-assessment.md.
  • Boundary markers: The provided reference code lacks explicit delimiters or instructions to ignore embedded commands within the analyzed user strings.
  • Capability inventory: The skill is configured with broad tool access, including Bash, Write, Edit, and WebFetch.
  • Sanitization: The current logic relies on heuristic pattern matching (e.g., searching for keywords like 'tense muscles') without demonstrating explicit sanitization of the input data.
  • [EXTERNAL_DOWNLOADS]: The skill instructions include the installation of several well-known scientific Python packages: heartpy, neurokit2, scipy, numpy, pandas, and matplotlib. These are standard tools for data science and physiological signal processing and are considered safe in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — hrv-alexithymia-expert