consult
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes medical data from external files which acts as a potential injection vector if the data contains malicious instructions designed to override the agent's behavior.
- Ingestion points: Medical data is ingested from
data/index.json,data/health-feeling-logs.json, and various JSON files in thedata/检查报告/directory as specified inSKILL.md. - Boundary markers: The prompt template for subagents in
SKILL.mdinterpolates patient data ({{加载相关的检查数据}}) without using delimiters or instructions to ignore potential commands embedded in the medical records. - Capability inventory: The skill utilizes
ReadandWritetools and performs subagent orchestration to generate comprehensive medical reports. - Sanitization: No evidence of sanitization or validation logic is present to filter out non-medical instructional content from the ingested files before they are passed to the subagents.
Audit Metadata