zenith-finance

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data which creates a surface for indirect prompt injection.\n
  • Ingestion points: Receipt images processed via OCR and raw text transaction descriptions enter the agent's context (SKILL.md).\n
  • Boundary markers: The instructions lack delimiters or specific directives to ignore potential commands embedded in receipt data.\n
  • Capability inventory: The agent has the capability to write to local financial files and perform budget calculations based on this input.\n
  • Sanitization: There is no logic provided to sanitize or validate the data parsed from receipts before it is written to the vault.\n- [DATA_EXFILTRATION]: The skill handles sensitive financial data (ledgers, balances, and net worth). It suggests syncing this data to Google Sheets, which is a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 12:08 PM
Security Audit — agent-trust-hub — zenith-finance