fincept-execution

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust security posture by requiring all code to pass strict validation sequences (clippy, type checks, and TDD) before completion. It specifically prohibits unsafe patterns such as hardcoded secrets, plaintext logging, or unparameterized SQL queries.
  • [COMMAND_EXECUTION]: The skill describes using Python's subprocess.run for validating script outputs during testing. This is a functional requirement for its role as a build agent and is mitigated by instructions to handle malformed input and separate error streams (stderr) from data output (stdout).
  • [PROMPT_INJECTION]: The skill features a structured task intake format which presents a surface for indirect prompt injection. However, the risk is effectively managed through mandatory TDD cycles, input validation requirements, and an explicit instruction to escalate uncertainty to a human or higher-level agent rather than executing potentially ambiguous commands.
  • [DATA_EXFILTRATION]: The skill includes instructions for creating WebSocket adapters and handling financial data, which are standard for its intended use case. It explicitly mandates the use of an established encryption path for broker credentials to prevent unauthorized exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — fincept-execution