tax-report-generator

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external, untrusted financial data (such as General Ledger files) which presents an indirect prompt injection surface.
  • Ingestion points: Financial data and spreadsheets provided by the user (e.g., General_Ledger.xlsx).
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to isolate the processed data from the agent's control logic.
  • Capability inventory: The skill possesses file-writing capabilities (audit_logs/) and uses system automation tools (desktop-rpa-computer-use).
  • Sanitization: There is no mention of filtering, escaping, or validating the content of the financial records before processing.
  • [COMMAND_EXECUTION]: The skill utilizes the desktop-rpa-computer-use tool to automate data entry into external legacy applications. This tool allows the agent to interact directly with the user's desktop environment based on data processed from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 12:50 PM
Security Audit — agent-trust-hub — tax-report-generator