just-fucking-cancel

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external financial data from bank CSV exports or the Plaid API, which presents a surface for indirect prompt injection attacks.
  • Ingestion points: Bank transaction records from various card issuers (e.g., Apple Card, Chase, Amex) or data pulled via the Plaid Transactions API as described in the workflow section of SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate untrusted transaction data (such as merchant names or descriptions) from agent instructions, which could allow malicious data to influence agent behavior.
  • Capability inventory: The skill possesses the capability to generate and populate HTML templates and use browser automation to navigate and perform actions on external websites.
  • Sanitization: No evidence of sanitization, filtering, or validation of transaction data is present in the instructions to prevent processing of malicious payloads embedded in transaction metadata.
  • [COMMAND_EXECUTION]: The workflow involves the use of browser automation to navigate to third-party service pages and execute cancellation actions, representing a high-autonomy capability.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — just-fucking-cancel