just-fucking-cancel

Warn

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted transaction data from bank statements and the Plaid API, which is then used to drive agent actions during browser automation. A malicious transaction description could potentially influence the agent's behavior.\n
  • Ingestion points: Bank transaction CSV files and the Plaid Transactions API (referenced in SKILL.md Step 1).\n
  • Boundary markers: Absent. No instructions are provided for the agent to treat transaction data as untrusted or to ignore embedded commands.\n
  • Capability inventory: Browser automation for navigating third-party websites and file-system access for reading statement exports (referenced in SKILL.md Step 5).\n
  • Sanitization: Absent. No sanitization or validation of transaction data is described before the data is processed or injected into the HTML template.\n- [DATA_EXFILTRATION]: The skill's core functionality requires the ingestion and processing of highly sensitive financial information, specifically bank and credit card transaction logs. While the documentation claims data remains local, the handling of such data within an AI session creates a potential exposure risk.\n- [COMMAND_EXECUTION]: The skill utilizes browser automation to perform functional tasks on external websites for subscription cancellation. This high-capability tool interacts with third-party environments based on parameters derived from user financial statements, posing a risk of misuse if the agent is influenced by malicious input.\n- [SAFE]: The skill references cancellation procedures for numerous well-known technology and media services (e.g., Apple, Amazon, Google, Microsoft, Netflix) in references/common-services.md. These links to official service pages are provided neutrally and are consistent with the skill's utility.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 14, 2026, 06:19 PM
Security Audit — agent-trust-hub — just-fucking-cancel