finance-report
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a benign workflow for generating data visualizations. It instructions the agent to read a local design guide and produce a self-contained HTML artifact for financial reporting. No evidence of credential theft, remote code execution, or persistence mechanisms was found.
- [SAFE]: The skill processes user-provided financial briefs, creating a theoretical surface for indirect prompt injection. 1. Ingestion points: The user brief described in the workflow. 2. Boundary markers: Absent in the prompt instructions. 3. Capability inventory: Limited to generating a static HTML artifact with inline CSS; no network, file-write, or subprocess capabilities are enabled. 4. Sanitization: No explicit sanitization of input data is defined. The overall risk is negligible given the lack of dangerous tools or actions.
Audit Metadata