mental-health-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from multiple external sources which provides an attack surface for instructions hidden within data to influence agent behavior.\n
  • Ingestion points: The skill reads from data-example/mental-health-tracker.json, data-example/sleep-tracker.json, data-example/fitness-tracker.json, and other log files in the data-example/ directory.\n
  • Boundary markers: The instructions do not specify any delimiters or boundary markers to differentiate between instructions and untrusted data during analysis.\n
  • Capability inventory: The skill is granted Read, Grep, Glob, Write, and Edit tools. These allow for comprehensive file system interaction which could be misused to expose or corrupt data if a prompt injection occurs.\n
  • Sanitization: There are no explicit steps provided to sanitize, validate, or filter the content extracted from the JSON files before it is processed by the agent or included in the final HTML report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:08 PM
Security Audit — agent-trust-hub — mental-health-analyzer