cognitive-toolkit
Warn
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses highly sensitive personal data, including genomic information stored at
~/Brains/genome/and biometric health data (HRV, sleep cycles, heart rate) via Apple Health MCP tools. - [COMMAND_EXECUTION]: The setup instructions (
hermes/setup-mac-mini.md) and operational logic involve shell script execution (scripts/nudge-check.sh), symlink creation, and crontab scheduling to facilitate background notification features. - [COMMAND_EXECUTION]: The provided crontab setup command hardcodes a specific Telegram recipient handle (
@glebkalinin). If used without modification, this could lead to the user's private session reminders or data being sent to the skill author's account. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted user input (descriptions of situations and personal thoughts) and interpolates this content into therapeutic protocols and structured markdown files saved to the local file system.
Audit Metadata