build-model

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a financial modeling tool, utilizing the vendor's own infrastructure (daloopa.com) for data sourcing and attribution.
  • [EXTERNAL_DOWNLOADS]: The skill uses the standard SheetJS (xlsx) library within a React environment to facilitate the Excel file download.
  • [DATA_EXFILTRATION]: No unauthorized data access or transmission to unknown third parties was observed. The data flow is limited to authenticated tool calls and linking to the source provider.
  • [COMMAND_EXECUTION]: No shell commands, privilege escalation, or persistence mechanisms are present in the skill instructions.
  • [PROMPT_INJECTION]: The skill ingests data from external financial sources (e.g., company profiles, KPIs) which is then used to generate a React artifact. This constitutes an indirect prompt injection surface where external content could potentially influence the code generation process; however, no evidence of exploitation was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 07:47 PM
Security Audit — agent-trust-hub — build-model