self-employed-planner

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [SAFE]: The skill operates as intended, providing a thin interface for financial planning calculations performed on a remote server. No malicious patterns were detected.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for the user to connect a remote MCP resource from https://ai.planfi.app/mcp/free. This is a documented configuration step for accessing the vendor's planning engine.
  • [DATA_EXFILTRATION]: The skill transmits user-provided financial data, such as business income and tax status, to the vendor's domain (planfi.app) for processing. This data flow is central to the skill's purpose and is directed to the service provider's infrastructure.
  • [PROMPT_INJECTION]: The skill ingests user input and processes remote tool output, creating a surface for indirect prompt injection. However, the skill lacks high-privilege capabilities (like arbitrary file writes or system command execution) that would allow for exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 04:50 PM
Security Audit — agent-trust-hub — self-employed-planner