financial-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses Python scripts that rely exclusively on the standard library (argparse, json, math, sys, statistics, typing). No third-party packages or unverifiable dependencies are required.
  • [SAFE]: No network operations, data exfiltration patterns, or external URL calls were found in the scripts or documentation.
  • [SAFE]: Input handling is performed via standard JSON loading and command-line arguments. The scripts do not use dangerous functions like eval(), exec(), or subprocess calls.
  • [SAFE]: No evidence of prompt injection, obfuscation, or persistence mechanisms was found in the skill metadata or instructional content.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local JSON files. However, the capability inventory is strictly limited to mathematical operations and text formatting, posing minimal risk as the ingested data is never executed or dynamically interpolated into shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:33 PM
Security Audit — agent-trust-hub — financial-analyst