accounts

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as gateway settlement reports and git logs.
  • Ingestion points: Financial transaction records from Stripe, Razorpay, Cashfree, PayU, and Paytm are processed in bookkeeping and audit modes, along with git commit logs for unbilled work detection.
  • Boundary markers: The skill uses the OpenAccountants Three-Outcome Protocol (CLASSIFIED, ASSUMED, NEEDS INPUT) to gate the processing of ambiguous data.
  • Capability inventory: The agent is authorized to use bash, run_command, and write_to_file for financial modeling and reconciliation tasks.
  • Sanitization: The LifeOS Vibeguard Protocol is employed to redact sensitive banking credentials and secret keys from agent outputs.
  • [COMMAND_EXECUTION]: The skill executes a local reconciliation script to process financial settlement batches.
  • Evidence: The documentation in SKILL.md and agents/openai.yaml authorizes the use of bun to run the scripts/reconcile-gateways.ts engine.
  • [SAFE]: The skill demonstrates security awareness by explicitly prohibiting the handling of live credentials and enforcing a zero-secret policy.
  • Evidence: SKILL.md contains specific instructions to mask financial secrets and defines clear boundaries for tax reserve management to prevent liquidity shocks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — accounts