fondo-core-workflow-b
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external tax evidence and expense classifications, which introduces a potential attack surface for instructions embedded in that data. Ingestion points: Processes external source records and expense classifications as described in Step 1 of the instructions. Boundary markers: No technical delimiters are specified for the input data, although the skill provides procedural instructions to exclude sensitive PII and bank details from the final output. Capability inventory: The skill utilizes platform tools including Read, Write, Edit, and Grep to interact with files. Sanitization: There are no technical sanitization steps for the data, but the skill mandates a human-in-the-loop reconciliation process with a finance professional and formal sign-off before any tax-related actions are taken.
Audit Metadata