skin-health-analyzer
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected. The medical disclaimer is a safety best practice rather than an injection.
- [DATA_EXFILTRATION]: No network operations (such as curl or fetch) or access to sensitive local file paths (like credentials or SSH keys) were found. The skill operates purely on health data patterns described in text.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets were identified within the document.
- [OBFUSCATION]: The content is written in clear Chinese and English. No Base64 encoding, zero-width characters, homoglyphs, or other techniques to hide content were detected.
- [REMOTE_CODE_EXECUTION]: There are no commands to download or execute external scripts, nor are there any package manager invocations (e.g., pip, npm).
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to ingest and process user health data (a potential attack surface), it lacks any executable tools or system-level capabilities that could be exploited via malicious input in this context. The risk remains at the base level for a descriptive skill.
- [NO_CODE]: The skill consists entirely of markdown instructions and metadata, with no associated scripts or binary files.
Audit Metadata