cpa-form-finder

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes links to the author's official website (deciqai.com) and GitHub repository (github.com/deciqai) for documentation, metadata, and updates. These are legitimate vendor resources used for providing skill context.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and tax logic. It does not include any Python or Node.js scripts, shell commands, or remote execution patterns.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths were detected. The skill focuses on tax form categorization based on user-provided narratives.
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override agent behavior, bypass safety filters, or extract system prompts. The language is professional and domain-specific.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process untrusted user input (client descriptions of financial events), it lacks exploitable capabilities such as file writing, network requests, or command execution. The output is limited to text-based lists for human review, resulting in negligible risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:14 AM
Security Audit — agent-trust-hub — cpa-form-finder