finance-expert
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a comprehensive knowledge base and operational instructions for financial modeling and SaaS metrics. No evidence of malicious intent or security bypass attempts was found.
- [INDIRECT_PROMPT_INJECTION]: The skill utilizes tools such as
WebSearch,WebFetch, andmcp__scoutto ingest untrusted data from the web. This creates a potential surface for indirect prompt injection attacks. - Ingestion points: Tools
WebFetch,WebSearch, andmcp__scout__readable_textallow external data to enter the agent context. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched content.
- Capability inventory: The skill is limited to reading files (
Read,Glob,Grep) and fetching web data; it does not have capabilities for file modification, code execution, or privilege escalation. - Sanitization: There are no explicit sanitization or validation steps defined for the data retrieved via the search and fetch tools.
Audit Metadata