rehabilitation
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely within its defined scope of rehabilitation management, utilizing the 'Read' and 'Write' tools exclusively for local data persistence in 'data/rehabilitation-tracker.json'.
- [SAFE]: Instructions focus on keyword extraction and JSON generation for health tracking, with no indicators of prompt injection, role-play bypasses, or attempts to override AI safety guidelines.
- [SAFE]: The skill includes explicit 'Medical Safety Boundaries' that prohibit the AI from providing medical prescriptions or diagnoses, adhering to safety best practices for health-related applications.
- [DATA_EXFILTRATION]: No network operations (curl, wget, fetch) or access to sensitive system paths (e.g., .ssh, .aws) were found. Data remains within the local environment.
- [REMOTE_CODE_EXECUTION]: There are no remote script downloads, package installations, or dynamic code execution patterns detected in the skill instructions or examples.
- [OBFUSCATION]: The content is presented in clear text (Chinese and English) without any Base64 encoding, hex escapes, or hidden Unicode characters.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided exercise and assessment data. While this creates a data ingestion surface, the risk is minimized by the skill's restricted toolset and the structured mapping of inputs to a predefined JSON schema.
Audit Metadata