tw-fintech-compliance

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate instructional content and regulatory frameworks for financial technology in Taiwan. No malicious command execution, data exfiltration patterns, or obfuscation were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a template for evaluating user-provided product descriptions against compliance standards. While this processing of untrusted data theoretically allows for indirect prompt injection attempts, the risk is minimal as the skill does not possess sensitive capabilities like file system modification or network access that could be exploited.
  • Ingestion points: SKILL.md (Product Classification and Licensing Pathway sections)
  • Boundary markers: None explicitly defined to separate user input from the report generation instructions.
  • Capability inventory: The skill is entirely knowledge-based and does not utilize tools for writing files, making network requests, or executing system commands.
  • Sanitization: None implemented for the product description data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:06 PM
Security Audit — agent-trust-hub — tw-fintech-compliance