finance-income-statement
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: No security issues or malicious patterns were identified in the skill instructions. The skill follows standard financial reporting workflows and contains no indicators of malicious intent.
- [NO_CODE]: The skill consists entirely of natural language instructions and formatting templates without any embedded scripts, executable code, or command-line operations.
- [PROMPT_INJECTION]: The skill processes external financial data, which presents an indirect prompt injection surface.
- Ingestion points: Financial data provided via ERP integration, spreadsheet uploads, or direct user input in SKILL.md Step 1.
- Boundary markers: Absent; no specific delimiters or instructions to ignore embedded commands within the ingested data are provided.
- Capability inventory: None; the skill instructions do not involve any subprocess calls, network writes, or file-system operations.
- Sanitization: Absent; the skill does not specify any validation or filtering for the ingested financial data.
Audit Metadata