biz-dcf

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive financial documentation and methodology for company valuation without any malicious instructions or prompt injection attempts.
  • [COMMAND_EXECUTION]: The skill includes a Python script (scripts/dcf.py) for performing calculations. Analysis of the source code confirms it uses standard libraries (argparse, json, sys) and performs only mathematical operations. It does not access the network, sensitive files, or execute dynamic code.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file path access, or network operations targeting external domains was found.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes financial data via user input or JSON files, the script treats these inputs as numerical values for calculation. There is no interpolation of untrusted data into system prompts or executable commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:06 PM
Security Audit — agent-trust-hub — biz-dcf