financial-analyst
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's functionality is entirely local and transparent. Analysis of the provided scripts (
ratio_calculator.py,dcf_valuation.py,budget_variance_analyzer.py, andforecast_builder.py) confirms they are strictly limited to performing deterministic financial calculations and formatting reports based on user-provided JSON data. No malicious commands, obfuscation, or data exfiltration vectors were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface because it processes external financial JSON files. However, this is assessed as safe because the skill lacks the high-privilege capabilities required for exploitation. Ingestion points: Theinput_fileargument used across all scripts to load financial statements and budget data. Boundary markers: The Phase 1 workflow requires the agent to explicitly confirm materiality thresholds and analysis objectives with the user. Capability inventory: Exhaustive review confirms no subprocess calls, execution of external code, network requests, or file-write operations. Sanitization: Input data is parsed using the standardjson.load()function and processed through type-safe mathematical operations.
Audit Metadata