manage-cashflow

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains strict negative constraints (referred to as a 'HARD GATE') designed to prevent the model from executing financial transactions. These instructions require the agent to lead with a refusal if money-movement intent is detected. These are safety-positive controls rather than malicious overrides.
  • [COMMAND_EXECUTION]: The skill interfaces with the 'airwallex' CLI binary. This is a legitimate vendor-provided tool required for the skill's stated purpose of treasury management. No unauthorized or arbitrary command execution patterns were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface as it processes information from invoices, supplier bills, and account names which could be controlled by third parties.
  • Ingestion points: Workflow steps 3 and 4 read data from external invoices (FINALIZED status) and global account transactions.
  • Boundary markers: The skill uses explicit 'HARD GATE' instructions and template-based refusals to isolate read-only operations from write-only execution.
  • Capability inventory: The skill is restricted to reading balances, listing invoices, and fetching indicative FX rates via the CLI. It explicitly lacks the capability to 'execute' or 'write' transfers.
  • Sanitization: The instructions mandate the use of business labels over raw IDs and require manual user confirmation for any hypothetical write action, providing a human-in-the-loop checkpoint.
  • [DATA_EXFILTRATION]: While the skill accesses sensitive financial data (balances and receivables), it operates within the authenticated environment of the Airwallex CLI. There are no patterns indicating the transmission of this data to unauthorized third-party domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 09:07 AM
Security Audit — agent-trust-hub — manage-cashflow