fondo-hello-world

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides informational guidance and links to official resources without including executable scripts or network-active code.\n- [NO_CODE]: No code or scripts are included within the skill package; instructions are primarily markdown-based guidance.\n- [INDIRECT_PROMPT_INJECTION]: The skill involves the agent processing external financial data, which is an ingestion surface for untrusted content. This is mitigated by strict output instructions.\n
  • Ingestion points: Bank transaction and payroll data sync details from the Fondo Dashboard (SKILL.md).\n
  • Boundary markers: The instructions explicitly forbid emitting account, transaction, payroll, or tax data (SKILL.md).\n
  • Capability inventory: The agent is restricted to Read, Write, Edit, and Grep tools.\n
  • Sanitization: The skill mandates the use of opaque test IDs and redacted failure references to ensure data privacy.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:45 AM
Security Audit — agent-trust-hub — fondo-hello-world