fhir-ig-translation

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install a sibling tool from the author's official GitHub repository (forschungsgruppe-digital-health/agent-skills). This is a legitimate extension of the skill's capabilities within the vendor's ecosystem.
  • [DYNAMIC_EXECUTION]: The script scripts/ig-translate.sh contains an embedded Python script for parsing local JSON files. This execution is scoped to the local environment and uses standard libraries to handle project metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests project-specific data. 1. Ingestion points: The skill reads files from fsh-generated/resources/*.json and input/pagecontent/*.md. 2. Boundary markers: No explicit delimiters or safety warnings are used for the content of these files. 3. Capability inventory: The skill utilizes Bash for running the bundled translation helper and Write tools as defined in SKILL.md. 4. Sanitization: The helper script uses standard Python json.load for parsing resource data, which provides basic structural validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:55 AM
Security Audit — agent-trust-hub — fhir-ig-translation