transaction-categorizer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted description_raw strings from financial transactions and a user-provided taxonomy JSON block.
  • Ingestion points: The transactions array and taxonomy block defined in the Input Contract section of SKILL.md are the primary entry points for external, untrusted data.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters (e.g., XML tags or triple quotes) to isolate the transaction descriptions from the agent's classification instructions in Step 3.
  • Capability inventory: No high-risk capabilities such as network operations, file system writes, or subprocess execution are present in the skill description; the scope is limited to data normalization and categorization.
  • Sanitization: While Step 1 (Normalize) cleans transaction strings for matching purposes (e.g., stripping vendor codes and geographical data), it does not provide sanitization against potential prompt injection payloads embedded within the raw transaction text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:34 PM
Security Audit — agent-trust-hub — transaction-categorizer