Security audit
Health Git
Security checks across malware telemetry and agentic risk
Overview
The skill is coherent and not obviously malicious, but it can write health records, approve health-intervention plans, and change safety rules while authentication is disabled by default.
Use this only with a trusted local Health Git service. Before using real health data, enable authentication, replace example keys, separate patient/reviewer/admin permissions, require human confirmation for PR reviews and rule changes, and verify the service code and data-retention behavior.
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
