treatment-plans
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes clinician-supplied JSON documentation, creating an ingestion surface for potentially malicious data embedded in interventions or fact statements.
- Ingestion points: Local JSON files loaded by validation scripts such as
scripts/validate_treatment_plan.py. - Boundary markers: The skill contains explicit 'Hard safety boundaries' and requires a mandatory 'DRAFT' notice on all outputs to prevent the agent from treating data as instructions.
- Capability inventory: All scripts are restricted to the local filesystem and Python standard library; no network, subprocess, or dynamic code execution capabilities are provided.
- Sanitization: Strict structural validation is enforced by
_common.py, including depth limits, node count restrictions, and schema verification. - [SAFE]: The skill operates entirely within the Python standard library, requiring no external packages or network connectivity.
- [SAFE]: Robust path validation is implemented in
_common.py, rejecting symlinks, network shares, and non-local paths to ensure the agent remains within authorized local directories.
Audit Metadata