ghealth

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions for using the ghealth command-line interface to interact with the Google Health API. This is the primary intended functionality of the skill.
  • [DATA_EXFILTRATION]: The skill facilitates the retrieval of sensitive health data (e.g., heart rate, blood glucose, sleep patterns) and includes options to export this data to local files using the -o flag. This behavior is consistent with the skill's stated purpose of being a health data query tool.
  • [PROMPT_INJECTION]: As the skill processes data retrieved from an external API (Google Health), there is a theoretical surface for indirect prompt injection if an attacker could manipulate the data stored in the user's health account. This risk is considered negligible given the context of health telemetry data.
  • Ingestion points: Data returned by ghealth CLI commands.
  • Boundary markers: None explicitly defined in the provided instructions.
  • Capability inventory: The skill has the capability to write data to the local file system using the -o parameter.
  • Sanitization: No specific sanitization or filtering of API output is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:34 AM
Security Audit — agent-trust-hub — ghealth