portfolio-rebalance-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to process data from various external sources, such as manual CSV/PDF uploads, pasted holdings, and AI-generated insights from Zocks. This creates a potential surface where untrusted data could influence the agent's behavior if malicious instructions were embedded within the data files or insights.
  • Ingestion points: Data enters the skill's context through portfolio data systems (Step 1), manual uploads of statements or exports (Step 1), and sentiment/context insights from Zocks (Step 4).
  • Boundary markers: The instructions do not specify the use of explicit delimiters or instructions to ignore embedded commands when processing these external data sources.
  • Capability inventory: The skill possesses significant capabilities, including invoking a data-validation subagent (claude-for-financial-advisors:holdings-sanity), calling financial connector tools (Orion, Addepar), and generating multiple file formats like Excel and PDF (Step 6).
  • Sanitization: The skill implements a comprehensive "Data-sanity gate" (Step 1) to validate the integrity of financial figures (e.g., magnitude, staleness, reconciliation). However, this process focuses on data quality and financial accuracy rather than sanitizing the content for potential prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:47 PM
Security Audit — agent-trust-hub — portfolio-rebalance-review