finta-hello-world

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data sources, specifically through CSV imports and investor discovery features. This creates a potential surface for indirect prompt injection where malicious instructions could be embedded in the ingested data.\n
  • Ingestion points: CSV import functionality described in 'Step 2: Add Target Investors' and external discovery via 'Aurora AI Prospecting' in SKILL.md.\n
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious content within the imported datasets.\n
  • Capability inventory: The skill utilizes Read, Write, and Edit tools as defined in its allowed-tools metadata to manage pipeline data and files.\n
  • Sanitization: There is no mention of sanitization or validation protocols for data retrieved from external CSV files or prospecting results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:45 AM
Security Audit — agent-trust-hub — finta-hello-world