tax-prep

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it is designed to ingest and process external financial data. \n
  • Ingestion points: Data entries from accounting systems (referenced as ~~бухгалтерии and ~~платежи) and user-provided CSV files.\n
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded commands in the source data.\n
  • Capability inventory: The skill has access to the 'Bash', 'WebFetch', and 'Read' tools.\n
  • Sanitization: No explicit validation or filtering logic for the input data is defined.\n Despite these factors, the skill implements strong human-in-the-loop checkpoints and explicit reminders that results are for review and do not constitute professional advice, which effectively mitigates the operational risk.\n- [COMMAND_EXECUTION]: The skill requests permission for the 'Bash' tool to facilitate data retrieval from accounting software. No suspicious shell commands, script generation patterns, or obfuscated payloads were detected within the skill's instructions.\n- [DATA_EXFILTRATION]: The skill handles sensitive financial data (income, expenses, and contractor information). However, its operations are limited to aggregating and presenting this data to the user or their accountant. No patterns indicating the transmission of this data to unauthorized external domains were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 07:18 PM
Security Audit — agent-trust-hub — tax-prep