skills/davepoon/buildwithclaude/recap/Gen Agent Trust Hub

recap

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes financial data retrieved from the query MCP tool to generate a narrative summary, which is a common attack surface for indirect prompt injection.
  • Ingestion points: Financial summary data, year-ago comparisons, and recurring bill data are ingested in steps 2, 3, and 4.
  • Boundary markers: The instructions do not define boundary markers (e.g., XML tags or delimiters) to separate instructions from the fetched financial data, nor do they instruct the agent to ignore any embedded commands within that data.
  • Capability inventory: The skill's capabilities are limited to narrative synthesis and text generation based on the fetched data. It does not perform sensitive file writes, external network requests (beyond the tool call), or shell command executions.
  • Sanitization: There is no evidence of sanitization or validation of the data fields (such as transaction notes or account names) before they are processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:48 PM