bookkeeping-automation

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (ls) against several sensitive local directories (~/.claude/skills/, ~/.agent/skills/, etc.) to perform environment discovery and identify other installed skills.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to install additional code using npx skills add from the AbsolutelySkilled/AbsolutelySkilled repository, which is not a verified or trusted source.
  • [PROMPT_INJECTION]: The 'Companion check' section uses instructional overrides to compel the agent to perform silent file system probing and automated installation suggestions upon activation, which bypasses standard conversational intent.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external financial data such as bank statements (CSV/OFX) and invoice OCR data without explicit boundary markers or sanitization logic, creating a surface for potential data-driven instruction injection.
  • Ingestion points: Bank statement imports, invoice data extraction, and billing system exports described in SKILL.md.
  • Boundary markers: Absent; there are no instructions to the agent to ignore or delimit instructions found within the processed financial data.
  • Capability inventory: The agent is granted capabilities for shell command execution (ls) and package management (npx).
  • Sanitization: Absent; the skill does not define filtering or validation for ingested financial records.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — bookkeeping-automation