smart-intake

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection attack surface through its processing of untrusted external financial data.\n
  • Ingestion points: Bank statements (PDF/CSV) and invoices are read from user-provided folders (SKILL.md, Step 2).\n
  • Boundary markers: There are no explicit delimiters or instructions defined to isolate untrusted content from the agent's logic.\n
  • Capability inventory: The skill has the ability to read files and write to the local file system, including creating 'engagement_state.json' and transaction logs (SKILL.md, Step 5).\n
  • Sanitization: The skill description does not include protocols for sanitizing or validating the contents of the ingested documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:04 AM
Security Audit — agent-trust-hub — smart-intake