Back to skill

Security audit

Patient Simulator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent CLI guide for installing and using AnnaAgent as a counseling patient simulator, with no hidden execution or exfiltration behavior found.

Before installing, understand that this skill will guide an agent to install and run an external AnnaAgent package, configure API-backed model services, and create local simulation state, logs, and possible memory files. Use non-sensitive test data, keep API keys in .env-style secret storage, review generated logs before sharing or publishing, and verify the external package and model endpoints match your trust requirements.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.