treatment-plans

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes clinician-supplied JSON documentation, creating an ingestion surface for potentially malicious data embedded in interventions or fact statements.
  • Ingestion points: Local JSON files loaded by validation scripts such as scripts/validate_treatment_plan.py.
  • Boundary markers: The skill contains explicit 'Hard safety boundaries' and requires a mandatory 'DRAFT' notice on all outputs to prevent the agent from treating data as instructions.
  • Capability inventory: All scripts are restricted to the local filesystem and Python standard library; no network, subprocess, or dynamic code execution capabilities are provided.
  • Sanitization: Strict structural validation is enforced by _common.py, including depth limits, node count restrictions, and schema verification.
  • [SAFE]: The skill operates entirely within the Python standard library, requiring no external packages or network connectivity.
  • [SAFE]: Robust path validation is implemented in _common.py, rejecting symlinks, network shares, and non-local paths to ensure the agent remains within authorized local directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — treatment-plans