heyma-pipeline-doctor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The diagnostic script
doctor.shand associated playbooks execute various system commands includingsystemctlfor service monitoring,sqlite3for ledger inspection,gsettingsfor desktop environment checks, andmcfor MinIO storage administration. - [DYNAMIC_EXECUTION]: The skill uses
python3heredocs and inline scripts to dynamically process JSON state data, verify library imports (such astorchandnemo), and execute CUDA smoke tests to ensure diarization functionality. - [DATA_EXFILTRATION]: The skill resolves live configuration by reading from the
/procfilesystem (e.g.,/proc/pid/environand/proc/pid/status) to identify active roots and ledger paths, and uses theopCLI to verify that required secrets are resolvable from 1Password without logging their values. - [EXTERNAL_DOWNLOADS]: The skill performs connectivity checks via
curlto external LLM provider endpoints (OpenRouter, Pokee) and MinIO storage services to verify availability and model presence. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the local pipeline ledger and transcript files during its diagnostic routines.
- Ingestion points: Data is pulled from the
wax.dbSQLite database andstate.jsonmirror. - Boundary markers: No specific delimiters or safety instructions are used when reading internal state.
- Capability inventory: The agent can execute system commands, restart services, and perform network requests.
- Sanitization: Diagnostic checks assume the integrity of the local ledger data without secondary sanitization.
Audit Metadata