finance-agent-skills
Pass
Audited by Gen Agent Trust Hub on Jun 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from multiple external channels, creating a surface for indirect prompt injection. Ingestion points: Data enters the agent context from Stripe (invoices), Gmail/AgentMail (triage), Intercom (support context), and external web pages via the browser_agent tool. Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags) or safety instructions to isolate external content from system prompts. Capability inventory: The agent can draft outbound emails, update Google Sheets, and use repository coding tools to implement automation. Sanitization: No sanitization or validation of external input is performed before it is processed.
- [SAFE]: No evidence of malicious code, obfuscation, or unauthorized data exfiltration was detected. The skill instructions follow best practices by requiring summaries before performing irreversible financial or bulk updates.
Audit Metadata