chief-finance

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and metadata do not contain any malicious patterns, obfuscated code, or attempts to bypass safety guardrails. All operations are confined to generating structured documentation and financial models within the project's local directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing data from other agent roles, which could theoretically contain malicious instructions.
  • Ingestion points: Data for the financial model (FINANCIAL_MODEL.md) is sourced from external artifacts like GROW-XXXX (marketing), HIRE-XXXX (HR), and PLT-XXXX (technology).
  • Boundary markers: The skill enforces a structured identification system (XXXX-ID) and specific markdown templates to organize and delimit external inputs.
  • Capability inventory: The agent's capabilities are restricted to document creation and reporting; no high-risk tools such as network requests, shell execution, or dynamic code evaluation are requested or used.
  • Sanitization: While explicit sanitization of ingested text is not defined, the skill mandates a human approval step (Executive Gate 1) before any financial strategy or commitment is finalized.
  • [COMMAND_EXECUTION]: No shell commands, subprocess calls, or system-level modifications are present in the skill.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any network operations, remote script downloads, or third-party package installations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:07 AM
Security Audit — agent-trust-hub — chief-finance