bad-debt-provision-check-free
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The core logic is implemented in a standalone JavaScript file using only Node.js standard libraries. It performs mathematical validations and does not access the network or sensitive system credentials.
- [EXTERNAL_DOWNLOADS]: The skill includes documentation for a paid version upgrade that involves running a command to install a payment tool from a well-known vendor (@alipay). This is a transparent commercial feature and does not constitute a hidden threat.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text or JSON files for financial verification. While it acts as a data ingestion point, the parser is restricted to identifying specific financial headers and numerical values, which minimizes the likelihood of the AI interpreting or executing malicious instructions hidden within the financial documents.
Audit Metadata