mushi-health

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses local configuration files and checks API key status as part of its intended diagnostic function. Instructions for adding keys use safe placeholders.
  • [REMOTE_CODE_EXECUTION]: The skill uses established CLI tools for monitoring and does not download or execute untrusted scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests log data and SQL results from the monitored system. Ingestion points include edge function logs and database queries; while it lacks explicit boundary markers, its capabilities are restricted to monitoring and reporting tasks.
  • [COMMAND_EXECUTION]: Shell commands are limited to predefined monitoring tasks such as doctor, status, and deploy check.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:56 AM
Security Audit — agent-trust-hub — mushi-health