finance-close-management
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external financial data provided by the user, such as ERP exports, payroll records, and general ledger entries. While this is necessary for its function, it creates a potential attack surface for indirect prompt injection. \n
- Ingestion points: User-uploaded CSV/Excel ERP exports and pasted general ledger data (as noted in the Problem Solving section). \n
- Boundary markers: The instructions do not specify explicit delimiters or "ignore instructions" tags to separate user financial data from the agent's logic. \n
- Capability inventory: The skill routes to
moai-officer:doc-xlsxfor document creation andmoai-writer:korean-humanizefor prose refinement. \n - Sanitization: No specific input validation or sanitization processes are described for the ingested financial records. \n- [EXTERNAL_DOWNLOADS]: The skill references established official domains for tax and financial information, including the National Tax Service (nts.go.kr), the 4 Major Insurances Information Link Center (4insure.or.kr), and the Bank of Korea (ecos.bok.or.kr). These are well-known, trusted governmental and institutional services used exclusively for informational lookup.
Audit Metadata