therapist-documentation
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to read environment definitions and configuration files, which commonly contain sensitive credentials and system secrets (Location: SKILL.md, Phase 1).
- [PROMPT_INJECTION]: The skill uses autonomous directives such as 'Do NOT ask the user questions' and 'Investigate the entire codebase thoroughly', which can override default agent behavior (Location: SKILL.md, Instructions).
- [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection. Ingestion points: entire codebase, configuration files, and environment definitions. Boundary markers: Absent. Capability inventory: comprehensive file reading and system mapping. Sanitization: Absent (Location: SKILL.md, Phase 1).
Audit Metadata