financial-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and associated scripts do not contain any malicious patterns or security risks. All logic is implemented using Python standard libraries without external dependencies.\n- [COMMAND_EXECUTION]: The skill executes local Python scripts to perform financial calculations. This behavior is documented and appropriate for the skill's purpose as a toolkit for financial analysts.\n- [DATA_EXFILTRATION]: No network operations (e.g., requests, curl, urllib) or attempts to access sensitive system files (e.g., credentials, SSH keys, environment files) were found. The tools operate strictly on data provided via command-line arguments.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface by reading external JSON files, but it lacks exploitable capabilities like network egress or system modification that would facilitate a high-risk injection attack. Numerical processing of financial data further reduces the likelihood of instruction-based overrides.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:16 PM
Security Audit — agent-trust-hub — financial-analyst