consult

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes medical data from external files which acts as a potential injection vector if the data contains malicious instructions designed to override the agent's behavior.
  • Ingestion points: Medical data is ingested from data/index.json, data/health-feeling-logs.json, and various JSON files in the data/检查报告/ directory as specified in SKILL.md.
  • Boundary markers: The prompt template for subagents in SKILL.md interpolates patient data ({{加载相关的检查数据}}) without using delimiters or instructions to ignore potential commands embedded in the medical records.
  • Capability inventory: The skill utilizes Read and Write tools and performs subagent orchestration to generate comprehensive medical reports.
  • Sanitization: No evidence of sanitization or validation logic is present to filter out non-medical instructional content from the ingested files before they are passed to the subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:07 PM
Security Audit — agent-trust-hub — consult