finance-agent-skills

Pass

Audited by Gen Agent Trust Hub on Jun 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from multiple external channels, creating a surface for indirect prompt injection. Ingestion points: Data enters the agent context from Stripe (invoices), Gmail/AgentMail (triage), Intercom (support context), and external web pages via the browser_agent tool. Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags) or safety instructions to isolate external content from system prompts. Capability inventory: The agent can draft outbound emails, update Google Sheets, and use repository coding tools to implement automation. Sanitization: No sanitization or validation of external input is performed before it is processed.
  • [SAFE]: No evidence of malicious code, obfuscation, or unauthorized data exfiltration was detected. The skill instructions follow best practices by requiring summaries before performing irreversible financial or bulk updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 9, 2026, 09:34 PM
Security Audit — agent-trust-hub — finance-agent-skills