finance-data-qc

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze data from external sources including databases, file systems, and full-text announcements. This inherently creates a surface for indirect prompt injection, particularly when analyzing disclosure events or research reports where malicious instructions could be embedded in the text. The skill addresses this risk through mandatory data desensitization and by focusing on structured quality metrics rather than following instructions within the data (found in SKILL.md and references/disclosure-event.md).
  • [DYNAMIC_EXECUTION]: The skill generates monitoring code in formats such as SQL, JavaScript, and Python based on identified data defects. While this is dynamic code generation, the skill provides specific guidelines to parameterize these outputs and keep them focused on data validation within defined budgets, which reduces the risk of arbitrary code execution (found in SKILL.md and references/deliverables.md).
  • [COMMAND_EXECUTION]: The skill explicitly mandates a read-only environment and prohibits Data Definition Language (DDL) and Data Manipulation Language (DML) operations, reducing the risk of unauthorized system changes or data destruction (found in SKILL.md and references/exploration.md).
  • [CREDENTIALS_UNSAFE]: Safety instructions are included to immediately halt operations if sensitive information such as plaintext passwords or private keys are discovered within connection strings or target data samples, preventing accidental credential exfiltration (found in SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:28 AM
Security Audit — agent-trust-hub — finance-data-qc