accounts
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as gateway settlement reports and git logs.
- Ingestion points: Financial transaction records from Stripe, Razorpay, Cashfree, PayU, and Paytm are processed in bookkeeping and audit modes, along with git commit logs for unbilled work detection.
- Boundary markers: The skill uses the OpenAccountants Three-Outcome Protocol (CLASSIFIED, ASSUMED, NEEDS INPUT) to gate the processing of ambiguous data.
- Capability inventory: The agent is authorized to use bash, run_command, and write_to_file for financial modeling and reconciliation tasks.
- Sanitization: The LifeOS Vibeguard Protocol is employed to redact sensitive banking credentials and secret keys from agent outputs.
- [COMMAND_EXECUTION]: The skill executes a local reconciliation script to process financial settlement batches.
- Evidence: The documentation in SKILL.md and agents/openai.yaml authorizes the use of bun to run the scripts/reconcile-gateways.ts engine.
- [SAFE]: The skill demonstrates security awareness by explicitly prohibiting the handling of live credentials and enforcing a zero-secret policy.
- Evidence: SKILL.md contains specific instructions to mask financial secrets and defines clear boundaries for tax reserve management to prevent liquidity shocks.
Audit Metadata