commerce-margin-calculator

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill functions as a mathematical calculator for business metrics. No dangerous commands, network access, or sensitive file interactions were identified.
  • [NO_CODE]: The skill contains only documentation and formulas. There are no associated Python or Node.js scripts.
  • [PROMPT_INJECTION]: Analysis of instructions found no attempts to bypass safety filters or override system constraints. The directive to exclude a specific reviewer agent (ai-slop-reviewer) appears to be a technical optimization for handling numeric/JSON data rather than a malicious bypass.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input (product names, prices) to generate JSON results. Mandatory Evidence Chain: 1. Ingestion points: Natural language input in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: No execution or network tools detected. 4. Sanitization: Absent. While this is an ingestion point for untrusted data, the lack of dangerous tools or system access ensures this surface is not exploitable in the current context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:42 PM
Security Audit — agent-trust-hub — commerce-margin-calculator