personal-finance-coach
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates tools for external data retrieval (
mcp__firecrawl__firecrawl_search,WebFetch) alongside powerful execution capabilities (Bash,Write,Edit). This configuration allows untrusted content from the web to be ingested into the agent's context where it might influence file system operations or command execution. - Ingestion points: Untrusted data enters via search and web fetch operations.
- Boundary markers: The skill does not define clear delimiters or "ignore external instructions" guardrails to isolate retrieved web content from the agent's core logic.
- Capability inventory: The skill is granted access to the
Bashshell and theRead,Write, andEdittools for file manipulation. - Sanitization: No explicit sanitization or filtering logic is prescribed for data fetched from remote web sources.
Audit Metadata