tres-report-advisor
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- Standard API Integration: The skill utilizes a GraphQL-based Model Context Protocol (MCP) to interact with TRES Finance APIs. This implementation follows standard practices for agent-based automation, allowing the skill to query report availability and initiate exports within the platform's controlled environment.
- Controlled Data Processing: The skill's primary function is to act as an advisory layer, mapping user requirements to a static catalog of 18 reports. It does not perform arbitrary network requests or access sensitive local file systems (such as SSH keys or environment secrets).
- Instructional Integrity: The instructions and reference documentation (report-catalog.md) are transparent and focused on the stated purpose. There are no indications of prompt injection, obfuscated commands, or hidden logic designed to bypass safety guardrails.
- No External Dependencies: The skill does not download or execute code from external sources. All logic is contained within the markdown instructions and the referenced internal catalog, minimizing the risk of supply chain vulnerabilities.
Audit Metadata