prepare-primary-statements
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions direct the agent to load files from the user's home directory, specifically '~/.claude/plugins/config/claude-for-accounting/firm-profile.md' and related paths. While these are plugin-specific configurations, accessing the home directory is a sensitive file operation.
- [PROMPT_INJECTION]: The skill processes Adjusted Trial Balance (ATB) data and client engagement documents, creating an attack surface for indirect prompt injection.
- Ingestion points: Adjusted Trial Balance data, client engagement README, and workspace files.
- Boundary markers: Absent; there are no explicit delimiters or warnings to ignore instructions embedded in the financial data.
- Capability inventory: Reading local configuration and project-specific files.
- Sanitization: Absent; the skill relies on a behavioral instruction ('Never fabricate numbers') rather than data sanitization or validation.
Audit Metadata