budgeting-forecasting
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown documentation and metadata. There are no scripts, binaries, or shell commands included for execution.
- [PROMPT_INJECTION]: The instructions describe a workflow where an agent ingests data from external systems to perform financial analysis and reporting, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: SKILL.md (instructions for pulling data from General Ledger actuals, CRM pipelines, and HR headcount records).
- Boundary markers: Absent. The instructions do not define delimiters or warnings for the agent to ignore embedded instructions in the ingested financial data.
- Capability inventory: The skill describes agent capabilities including reading from external databases/files (GL, CRM, HR), writing to files (budget models, board decks), and generating alerts.
- Sanitization: Absent. There is no mention of validating, filtering, or escaping external content before it is processed by the agent.
Audit Metadata