hrv-alexithymia-expert
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests physiological data and user-provided descriptions of physical sensations to identify emotional states and provide vocabulary training.
- Ingestion points: Data enters the agent's context through parameters like
rr_intervalsandbody_signalsused in thedetect_emotional_stateandexpand_emotional_vocabularyfunctions located inreferences/hrv-metrics.mdandreferences/alexithymia-assessment.md. - Boundary markers: The provided reference code lacks explicit delimiters or instructions to ignore embedded commands within the analyzed user strings.
- Capability inventory: The skill is configured with broad tool access, including
Bash,Write,Edit, andWebFetch. - Sanitization: The current logic relies on heuristic pattern matching (e.g., searching for keywords like 'tense muscles') without demonstrating explicit sanitization of the input data.
- [EXTERNAL_DOWNLOADS]: The skill instructions include the installation of several well-known scientific Python packages:
heartpy,neurokit2,scipy,numpy,pandas, andmatplotlib. These are standard tools for data science and physiological signal processing and are considered safe in this context.
Audit Metadata