transaction-categorizer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted
description_rawstrings from financial transactions and a user-providedtaxonomyJSON block. - Ingestion points: The
transactionsarray andtaxonomyblock defined in the Input Contract section ofSKILL.mdare the primary entry points for external, untrusted data. - Boundary markers: Absent. The instructions do not specify the use of delimiters (e.g., XML tags or triple quotes) to isolate the transaction descriptions from the agent's classification instructions in Step 3.
- Capability inventory: No high-risk capabilities such as network operations, file system writes, or subprocess execution are present in the skill description; the scope is limited to data normalization and categorization.
- Sanitization: While Step 1 (Normalize) cleans transaction strings for matching purposes (e.g., stripping vendor codes and geographical data), it does not provide sanitization against potential prompt injection payloads embedded within the raw transaction text.
Audit Metadata