loan-decoder

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a set of instructions for analyzing financial documents. It does not contain any malicious code, obfuscation, or persistence mechanisms.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill processes sensitive user-provided loan information, it lacks any tools or commands (such as network requests) to exfiltrate this data. It operates purely within the conversational context.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute any external scripts or packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text (loan offers), which is a potential surface for indirect prompt injection. However, since the skill has no high-risk capabilities like file system access, network operations, or shell execution, the impact of such an injection is negligible.
  • [COMMAND_EXECUTION]: No shell commands or system-level operations are invoked by this skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 08:43 AM
Security Audit — agent-trust-hub — loan-decoder