travel-health-analyzer

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of external data files.
  • Ingestion points: Data is read from data/travel-health-tracker.json and data-example/travel-health-tracker.json to generate reports and emergency cards.
  • Boundary markers: The instructions do not define clear delimiters or include warnings to ignore instructions embedded within the health data fields.
  • Capability inventory: The skill has Write access to the local filesystem, which could be abused if malicious instructions are processed from the input data.
  • Sanitization: There is no evidence of sanitization or validation of the data content before it is interpolated into reports or emergency cards.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 12:39 AM