saas-metrics

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown documentation, YAML templates, and mathematical formulas for financial reporting. No executable scripts, binaries, or installation commands are provided.
  • [SAFE]: No evidence of prompt injection, obfuscation, data exfiltration, or persistence mechanisms was found. The skill's stated purpose (SaaS metrics analysis) aligns with its implementation.
  • [DATA_EXPOSURE]: While the skill references sensitive financial tools (Stripe, Chargebee), it does so via standard MCP tool definitions and contains no hardcoded credentials or unauthorized access patterns.
  • [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process data from external financial platforms, it has a theoretical surface for indirect prompt injection if transaction data contains malicious text. However, this is a general risk of data-processing skills and no specific vulnerability exists in the skill's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:48 AM
Security Audit — agent-trust-hub — saas-metrics