finance-income-statement

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security issues or malicious patterns were identified in the skill instructions. The skill follows standard financial reporting workflows and contains no indicators of malicious intent.
  • [NO_CODE]: The skill consists entirely of natural language instructions and formatting templates without any embedded scripts, executable code, or command-line operations.
  • [PROMPT_INJECTION]: The skill processes external financial data, which presents an indirect prompt injection surface.
  • Ingestion points: Financial data provided via ERP integration, spreadsheet uploads, or direct user input in SKILL.md Step 1.
  • Boundary markers: Absent; no specific delimiters or instructions to ignore embedded commands within the ingested data are provided.
  • Capability inventory: None; the skill instructions do not involve any subprocess calls, network writes, or file-system operations.
  • Sanitization: Absent; the skill does not specify any validation or filtering for the ingested financial data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:08 PM
Security Audit — agent-trust-hub — finance-income-statement