tax-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions mandate the creation of granular audit logs in audit_logs/Audit_Trail_YYYYMM.xlsx and .csv. These logs capture detailed transaction data, including exact cell values and checksums. While intended for audit purposes, storing sensitive financial inputs and outputs in local files creates an exposure risk if the local environment is not strictly controlled.
  • [PROMPT_INJECTION]: The skill processes untrusted financial documents which serves as an ingestion point for indirect prompt injection. Because the agent coordinates powerful automation tools (web and desktop RPA), maliciously formatted data could attempt to manipulate the tax filing process.
  • Ingestion points: Financial documents and tax requests provided by the user in SKILL.md.
  • Boundary markers: Not explicitly defined in the provided instructions.
  • Capability inventory: File system writes to audit_logs/ and delegation to RPA-capable agents for web and desktop automation.
  • Sanitization: No input sanitization or validation steps are outlined before processing or delegating data to specialist agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 12:50 PM
Security Audit — agent-trust-hub — tax-orchestrator