surgery

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted natural language input from users to generate structured medical records. This creates an attack surface where malicious instructions embedded in surgical descriptions could potentially manipulate the agent's logic or corrupt stored data.\n
  • Ingestion points: Natural language input describing surgical history and medical implants provided by the user.\n
  • Boundary markers: Absent; the skill does not define specific delimiters or instructions to isolate the user-provided data from system-level instructions.\n
  • Capability inventory: The skill utilizes the Write tool to create and modify JSON files within the data/ directory, including an index file and dated surgical records.\n
  • Sanitization: Absent; the instructions rely on the model's extraction capabilities without explicit requirements for validation, escaping, or filtering of the input before it is written to the file system.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 05:26 AM
Security Audit — agent-trust-hub — surgery