budgeting-planning
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (
ls) to discover installed skills in specific local directories like~/.claude/skills/, which is an automated environment discovery behavior. - [DATA_EXFILTRATION]: The skill probes the user's environment by listing contents of various application-specific directories (
~/.claude/skills/,~/.agent/skills/, etc.), exposing the local directory structure and software footprint to the agent's context. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes external financial data (e.g., revenue targets, headcount models) provided in user prompts without implementing boundary markers or sanitization, while also having access to shell tools.
- Ingestion points: Financial spreadsheets and budget descriptions provided by the user in natural language prompts.
- Boundary markers: No delimiters or safety instructions are used to distinguish between data and instructions during processing.
- Capability inventory: The agent is explicitly told to use shell commands for environmental checks and to propose
npxcommands. - Sanitization: No validation or escaping is applied to the ingested financial data.
Audit Metadata