personal-finance-coach

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates tools for external data retrieval (mcp__firecrawl__firecrawl_search, WebFetch) alongside powerful execution capabilities (Bash, Write, Edit). This configuration allows untrusted content from the web to be ingested into the agent's context where it might influence file system operations or command execution.
  • Ingestion points: Untrusted data enters via search and web fetch operations.
  • Boundary markers: The skill does not define clear delimiters or "ignore external instructions" guardrails to isolate retrieved web content from the agent's core logic.
  • Capability inventory: The skill is granted access to the Bash shell and the Read, Write, and Edit tools for file manipulation.
  • Sanitization: No explicit sanitization or filtering logic is prescribed for data fetched from remote web sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:53 AM
Security Audit — agent-trust-hub — personal-finance-coach