finance-district

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the official @financedistrict/fdx package from the npm registry. This package is the designated command-line interface for the Finance District platform and is maintained by the skill's author.
  • [COMMAND_EXECUTION]: The skill utilizes the fdx CLI tool via the Bash tool to perform operations such as creating wallets, sending tokens, and managing merchant Points of Service. All command usage is restricted to the platform's own tooling as defined in the skill's configuration.
  • [PROMPT_INJECTION]: A potential surface for indirect prompt injection exists during the x402 payment flow where the agent processes payment requirements from external resource servers.
  • Ingestion points: HTTP 402 response bodies from external URLs provided by users or during task execution (references/x402-payment-flow.md).
  • Boundary markers: None explicitly provided in the instructions for parsing external data.
  • Capability inventory: Shell access for fund transfers, swaps, and merchant key management via the fdx CLI.
  • Sanitization: Not explicitly implemented in prompts; however, the skill mandates a 'Pre-Operation Checklist' that requires human confirmation for all irreversible actions.
  • [SAFE]: The skill implements strong safety patterns, including a mandatory human-in-the-loop confirmation step for all fund-moving operations and detailed guidance on secure authentication using official email OTP flows.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 07:34 AM
Security Audit — agent-trust-hub — finance-district