mental-health-clinic

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses the ~/.claude/projects/ directory to record telemetry data. This is a sensitive location used by the platform to store project-specific metadata and potentially private session history, making it a target for data exposure.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes external codebases without implementing security boundaries or sanitization.\n
  • Ingestion points: Files and modules within the target codebase identified during clinical platform discovery.\n
  • Boundary markers: Absent; the skill does not use delimiters or instructions to ignore embedded prompts within the data being analyzed.\n
  • Capability inventory: File system read access to the target codebase and file system write access to the docs/ and ~/.claude/projects/ directories.\n
  • Sanitization: Absent; external content is processed and incorporated into the analysis without escaping or validation.\n- [PROMPT_INJECTION]: The skill employs strong directive language, such as "Do NOT ask the user questions," to enforce autonomous operation and minimize user interaction, which reduces the opportunity for human oversight during potentially dangerous operations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — mental-health-clinic