ynab-budget-review

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes transaction memos and payee names which are external inputs that could theoretically contain instructions to override the agent's behavior.
  • Ingestion points: Financial data including transaction details, payees, and memos are read from the YNAB API into the agent context during the 'Initial review' phase.
  • Boundary markers: The skill does not provide explicit delimiters or instructions to the agent to treat transaction data as untrusted text.
  • Capability inventory: The agent has the ability to perform significant mutations on the user's budget, such as moving funds, approving transactions, and changing account balances, as detailed in the 'Apply approved changes' section.
  • Sanitization: The skill strongly mitigates these risks by requiring explicit, grouped user confirmation before any action is taken and performing a read-back verification after completion to ensure results match expectations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:38 AM
Security Audit — agent-trust-hub — ynab-budget-review