financial-modeling
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data, assumptions, and management forecasts, creating a surface for potential indirect prompt injection attacks.\n
- Ingestion points: The instructions in
SKILL.mddirect the agent to "Use provided data first" and "Preserve supplied assumptions" when building models.\n - Boundary markers: There are no explicit instructions for the agent to use delimiters or to disregard instructions embedded within user-supplied data files.\n
- Capability inventory: The skill utilizes "available calculation tools for material arithmetic" as described in
SKILL.md, implying access to a shell or code interpreter to perform arithmetic and link workbook outputs.\n - Sanitization: The skill lacks mention of sanitizing, validating, or escaping external content before it is processed by the agent or passed to calculation tools.
Audit Metadata