finance-close-management

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external financial data provided by the user, such as ERP exports, payroll records, and general ledger entries. While this is necessary for its function, it creates a potential attack surface for indirect prompt injection. \n
  • Ingestion points: User-uploaded CSV/Excel ERP exports and pasted general ledger data (as noted in the Problem Solving section). \n
  • Boundary markers: The instructions do not specify explicit delimiters or "ignore instructions" tags to separate user financial data from the agent's logic. \n
  • Capability inventory: The skill routes to moai-officer:doc-xlsx for document creation and moai-writer:korean-humanize for prose refinement. \n
  • Sanitization: No specific input validation or sanitization processes are described for the ingested financial records. \n- [EXTERNAL_DOWNLOADS]: The skill references established official domains for tax and financial information, including the National Tax Service (nts.go.kr), the 4 Major Insurances Information Link Center (4insure.or.kr), and the Bank of Korea (ecos.bok.or.kr). These are well-known, trusted governmental and institutional services used exclusively for informational lookup.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — finance-close-management