healthcare-eval-harness
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected in this skill. The skill provides legitimate documentation and automation scripts for healthcare application testing.
- [COMMAND_EXECUTION]: The skill provides examples of shell commands using
npx jest,jq, andbc. These are standard tools used for automated testing and JSON processing in development environments and do not represent a security risk in this context. - [REMOTE_CODE_EXECUTION]: The instructions include
npx jest, which executes a package from the registry. This is standard behavior for a JavaScript testing harness and is used appropriately here. - [INDIRECT_PROMPT_INJECTION]: The skill describes processes for ingesting and reporting on test data.
- Ingestion points: Test output files processed via
jq(SKILL.md). - Boundary markers: Standard command-line redirection and piping.
- Capability inventory: Subprocess execution restricted to local testing tools.
- Sanitization: Not applicable as it primarily handles numeric pass/fail counts.
- [METADATA_POISONING]: The metadata includes attribution to a healthcare provider and a specific doctor. While the author 'eugene-ee' differs from the 'origin' metadata field, this appears to be a standard attribution for contributed content and does not show signs of deceptive intent to bypass security controls.
Audit Metadata