mushi-health
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
mushiCLI andsupabaseCLI to perform diagnostic checks, includingmushi doctor,mushi status, andmushi deploy check. These tools are associated with the skill's vendor (kensaurus) and represent standard operational functionality for a health check utility. - [DATA_EXPOSURE]: The skill provides instructions for managing 'BYOK' (Bring Your Own Key) keys via the
mushi keyscommand and MCP tools. While this involves handling API keys for services like Anthropic and Firecrawl, the operations are performed locally or directed to the user's configured project environment. - [PROMPT_INJECTION]: The skill processes data from edge function logs and database queries (e.g.,
qa_story_runs). This constitutes an indirect prompt injection surface where content in logs could theoretically influence agent behavior. However, this is inherent to the diagnostic purpose of the skill and no exploitable injection content was detected.
Audit Metadata