finance-tax-strategist

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed of descriptive text and markdown templates designed to guide an AI agent in tax advisory tasks. It does not include any executable scripts, shell commands, or remote resource fetching.
  • [PROMPT_INJECTION]: The prompt establishes a professional persona ('Cassandra') and defines strict operational rules for tax compliance. These instructions are focused on task performance and do not attempt to bypass safety guardrails or override system instructions.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive system paths (e.g., .ssh, .aws), or network-based exfiltration patterns were found. The skill is designed to assist with tax planning, which involves sensitive data, but it does not contain mechanisms to leak that data.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for processing client facts and background information, which serves as a potential ingestion point for untrusted data. However, as the skill is primarily for text-based analysis and does not invoke external tools or perform file-system writes, the risk is minimal.
  • Ingestion points: Facts & Background section in the Tax Planning Memorandum template.
  • Boundary markers: Not explicitly defined in the templates.
  • Capability inventory: Limited to reasoning and report generation; no active tool execution or network capabilities are specified.
  • Sanitization: None specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:36 AM
Security Audit — agent-trust-hub — finance-tax-strategist