israeli-celiac-navigator
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill documentation references several external URLs for authoritative information, such as the Schneider Children's Medical Center and the Israeli Ministry of Health. These targets are recognized medical and governmental institutions, and the references are purely informational with no automated script execution, package installation, or remote code patterns involved.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an ingestion surface for untrusted data via user queries and processed reference files. Ingestion points: User queries about symptoms and rights. Boundary markers: Responses are strictly mandated to include medical disclaimers, and instructions prioritize physical packaging over provided shortlists. Capability inventory: The skill lacks tool-use definitions, shell execution, or file-writing functions. Sanitization: Strict instructional guardrails prevent the agent from issuing medical diagnoses or unverified safety claims.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network communication patterns were found. The skill does not access local sensitive directories or secrets.
- [OBFUSCATION]: Systematic analysis of all skill files, including the Hebrew instructions and JSON evidence data, revealed no use of base64 encoding, zero-width characters, homoglyphs, or other obfuscation techniques.
- [METADATA_POISONING]: The skill metadata and descriptions are consistent with the provided instructions and reference files, with no deceptive claims or hidden instructions detected.
Audit Metadata