financial-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's functionality is entirely local and transparent. Analysis of the provided scripts (ratio_calculator.py, dcf_valuation.py, budget_variance_analyzer.py, and forecast_builder.py) confirms they are strictly limited to performing deterministic financial calculations and formatting reports based on user-provided JSON data. No malicious commands, obfuscation, or data exfiltration vectors were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface because it processes external financial JSON files. However, this is assessed as safe because the skill lacks the high-privilege capabilities required for exploitation. Ingestion points: The input_file argument used across all scripts to load financial statements and budget data. Boundary markers: The Phase 1 workflow requires the agent to explicitly confirm materiality thresholds and analysis objectives with the user. Capability inventory: Exhaustive review confirms no subprocess calls, execution of external code, network requests, or file-write operations. Sanitization: Input data is parsed using the standard json.load() function and processed through type-safe mathematical operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:43 PM
Security Audit — agent-trust-hub — financial-analyst