fsi-command-ic-memo

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is purely instructional and defines a text-based workflow for drafting financial documents. No malicious patterns such as prompt injection, data exfiltration, or obfuscation were detected.
  • [NO_CODE]: The skill does not include any scripts, executable files, or configuration that would allow for command execution or remote code loading.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to ingest external materials (due diligence findings, financial analysis) to generate memos, which represents a theoretical indirect prompt injection surface, the risk is minimal as the skill instructions explicitly mandate that final artifacts be marked for human review.
  • Ingestion points: Processes user-provided "due diligence findings", "financial analysis", and "available materials".
  • Boundary markers: Not explicitly defined in the prompt interpolation.
  • Capability inventory: No executable capabilities or tool access (beyond standard text generation) are defined within the skill.
  • Sanitization: No explicit sanitization or filtering of input materials is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 12:08 PM
Security Audit — agent-trust-hub — fsi-command-ic-memo