skills/findbene/skills/cfo-advisor/Gen Agent Trust Hub

cfo-advisor

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: A comprehensive audit of the skill's instructions, documentation, and Python scripts confirmed they are limited to legitimate financial advisory and modeling tasks. The scripts use only the Python standard library and do not perform network operations, access sensitive system files, or execute obfuscated code.
  • [PROMPT_INJECTION]: The skill is configured to ingest and analyze data from a local company-context.md file. While this is a core feature for personalized financial advice, it represents a potential indirect prompt injection surface.
  • Ingestion points: The skill reads from company-context.md as instructed in the Context Integration section of SKILL.md.
  • Boundary markers: The prompt lacks specific delimiters or explicit instructions for the agent to disregard potential adversarial commands within the context file.
  • Capability inventory: The agent has access to shell tools (Bash, Glob, Grep, Read) and can execute local Python analysis scripts.
  • Sanitization: No explicit sanitization or input validation logic is applied to the context file's content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:12 AM
Security Audit — agent-trust-hub — cfo-advisor