saas-metrics
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown documentation, YAML templates, and mathematical formulas for financial reporting. No executable scripts, binaries, or installation commands are provided.
- [SAFE]: No evidence of prompt injection, obfuscation, data exfiltration, or persistence mechanisms was found. The skill's stated purpose (SaaS metrics analysis) aligns with its implementation.
- [DATA_EXPOSURE]: While the skill references sensitive financial tools (Stripe, Chargebee), it does so via standard MCP tool definitions and contains no hardcoded credentials or unauthorized access patterns.
- [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process data from external financial platforms, it has a theoretical surface for indirect prompt injection if transaction data contains malicious text. However, this is a general risk of data-processing skills and no specific vulnerability exists in the skill's logic.
Audit Metadata