accounting

Warn

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a 'GLOBAL PROTOCOLS' section that uses mandatory language to override the agent's default reasoning and operational behavior. Instructions such as 'No cognitive labor occurs outside of a defined mode' and 'You do not trust LLM probability' are designed to strictly constrain the model's autonomy and decision-making logic.
  • [COMMAND_EXECUTION]: The instructions mandate the use of an 'ExecutionProxy Interface' for all terminal actions, requiring a specific prefix ('rtk') for shell commands (e.g., 'rtk npm test'). This steers the agent's tool-use capabilities through a custom interface defined within the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external sources, including payment processor transactions (Stripe) and web content (BrowserOS), which presents a potential attack surface for indirect prompt injection.
  • Ingestion points: Data from Stripe, accounting software, and BrowserOS web content (SKILL.md).
  • Boundary markers: No explicit delimiters are specified for separating untrusted data from agent instructions.
  • Capability inventory: The agent has access to terminal execution via the 'rtk' proxy and file writing via the 'MemoryStore' interface (SKILL.md).
  • Sanitization: The instructions include a high-level directive to redact PII and secrets, but do not provide specific sanitization or validation protocols for handled data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 27, 2026, 07:36 AM
Security Audit — agent-trust-hub — accounting