price-check

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests data from external financial platforms which may contain untrusted content.
  • Ingestion points: Revenue data, product/service names, and COGS from QuickBooks; gross sales data from PayPal.
  • Boundary markers: None specified. The skill does not define delimiters or specific instructions to ignore embedded commands within the retrieved data.
  • Capability inventory: The skill is configured with access to the Bash, WebFetch, and Read tools.
  • Sanitization: The instructions do not include steps for validating, escaping, or filtering data retrieved from external APIs before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — price-check