month-heads-up

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external accounting and payment systems which could theoretically contain malicious instructions embedded by third parties or within transaction descriptions. \n
  • Ingestion points: The skill reads financial data from ~~бухгалтерия (1С, MoySklad) and ~~платежи (YuKassa, Tinkoff, bank statements) as described in SKILL.md. \n
  • Boundary markers: The skill does not define clear delimiters or provide instructions to the agent to ignore potentially malicious embedded content within the ingested financial records. \n
  • Capability inventory: The skill is configured with access to Bash, WebFetch, and Read tools. \n
  • Sanitization: There is no evidence of data validation, filtering, or sanitization before the external content is processed by the agent. \n- [DATA_EXFILTRATION]: The skill accesses highly sensitive financial information, including current cash balances and accounts receivable. While this is the primary purpose of the skill, the combination of sensitive data access and the WebFetch tool creates a technical surface for data exfiltration if the agent's behavior is compromised. \n- [COMMAND_EXECUTION]: The skill requests permission to use the Bash tool in its frontmatter. This allows the agent to execute shell commands to process data or interact with the environment, which significantly increases the potential impact of an injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:25 PM
Security Audit — agent-trust-hub — month-heads-up