financial-model

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions do not contain any attempts to override safety filters or bypass system guidelines. The instructional content is focused solely on financial modeling best practices.
  • [DATA_EXFILTRATION]: No patterns indicative of data exfiltration were found. The skill does not access sensitive system files (e.g., SSH keys, AWS credentials) or perform unauthorized network requests.
  • [COMMAND_EXECUTION]: The skill includes a utility script, scripts/verify.sh, which is used to validate the integrity of generated model.csv files. This script uses common Unix utilities like awk and grep to perform read-only checks for cash continuity and mathematical tie-outs. It does not execute arbitrary or dangerous commands.
  • [REMOTE_CODE_EXECUTION]: There are no occurrences of remote script downloads or dynamic execution of untrusted code. All logic is contained within the provided skill files.
  • [OBFUSCATION]: The skill content is presented in clear text without the use of Base64 encoding, zero-width characters, or other obfuscation techniques designed to hide malicious intent.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied startup scenarios to generate models. It follows best practices by recommending the use of structured CSV output and a separate validation script to handle the data, which minimizes the risk of the agent misinterpreting data as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — financial-model