post

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes local Python scripts post_journals.py and roll_tb.py to perform accounting calculations. This is consistent with the skill's stated purpose of automating the trial balance process.
  • [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it processes data from journals.json to complete tasks.
  • Ingestion points: Data is ingested from the journals.json file mentioned in the completion criteria.
  • Boundary markers: No specific delimiters or safety instructions are used to isolate ingested data from the system prompt.
  • Capability inventory: The skill is capable of executing local Python scripts for data processing, but lacks network or high-privilege access.
  • Sanitization: No explicit data sanitization or validation logic is defined in the markdown instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 02:12 PM
Security Audit — agent-trust-hub — post