dinero-regnskab
Warn
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to start a browser with remote debugging enabled (
--remote-debugging-port=9222) and to install theplaywrightpackage. It also stores the browser's user data profile in/tmp/dinero-profile, which is a shared directory that may not be sufficiently secured on all systems, potentially exposing session cookies.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from bank statements, which is a potential injection vector.\n - Ingestion points: Text extracted from PDF bank statements using
pdftotext. (Reference: Workflow section inSKILL.md)\n - Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in the prompt templates.\n
- Capability inventory: Access to financial records, ability to create/delete vouchers, and shell execution capabilities.\n
- Sanitization: No sanitization or filtering of the ingested bank statement text is implemented beyond basic whitespace removal.\n- [DYNAMIC_EXECUTION]: The skill uses
page.evaluate()to execute JavaScript within the context of the authenticated web session to interact with the Dinero API. This method allows the agent to perform actions as the user without needing separate API credentials.
Audit Metadata