data-financial-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external financial data, annual reports, and business scenarios, which are untrusted inputs. This creates an attack surface where malicious instructions could be embedded within the financial data (e.g., within descriptive text or notes).
- Ingestion points: Processes financial statements and annual reports as described in the SKILL.md body and instructions.
- Boundary markers: No specific delimiters or 'ignore instructions' warnings are provided to help the agent distinguish between data and embedded malicious commands.
- Capability inventory: The skill currently has no code components, tool invocations, or network access requirements, which significantly limits the impact of a potential injection attack.
- Sanitization: No input validation, escaping, or sanitization steps are defined for the data processed by the agent.
Audit Metadata