close-month

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, which could potentially contain malicious instructions targeting the agent context.
  • Ingestion points: External data is ingested from accounting systems (referred to as ~~бухгалтерия) and various payment sources (referred to as ~~платежи) such as Yookassa, Tinkoff, and bank statements.
  • Boundary markers: The skill does not define specific boundary markers or delimiters to isolate untrusted external data from the primary instructions or system context.
  • Capability inventory: The skill is authorized to use the Read, WebFetch, and Bash tools. It performs file writing operations to generate and save .xlsx and .pdf reports to specified storage locations (~~хранилище).
  • Sanitization: The instructions do not describe any sanitization, validation, or escaping processes for the external data before it is processed or used to generate financial summaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:25 PM
Security Audit — agent-trust-hub — close-month