adhd-friendly
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is primarily instructional, guiding the agent's communication style (e.g., action-first, executable steps, orientation). It does not contain commands for network access, sensitive file manipulation, or persistence.
- [INDIRECT_PROMPT_INJECTION]: The skill instructions include strong boundary markers and a 'Pre-send gate' to verify that the agent preserves the user's actual tasks, facts, and safety requirements when adapting the presentation style. It explicitly states that safety and user instructions outrank formatting defaults. Evidence chain:
- Ingestion points: User queries (SKILL.md).
- Boundary markers: Explicit 'Operating contract' and 'Safety and clinical boundaries' sections require preserving safety and authority (SKILL.md).
- Capability inventory: No unsafe tool execution or file-write capabilities are requested or used within the skill instructions themselves.
- Sanitization: Relies on the agent's existing safety guardrails and the 'Pre-send gate' logic.
- [COMMAND_EXECUTION]: The package includes Python validation scripts (validate.py, test_skill.py) intended for developer-side package verification. These scripts use standard Python libraries and do not contain instructions for the agent to execute dangerous commands in the user's environment.
Audit Metadata