prepare-property-tax-appeal

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external real-property records and listings, creating a potential attack surface.
  • Ingestion points: Workflow steps in SKILL.md (Steps 3, 4, 6, and 10) ingest data from assessor pages, search results, and owner-provided attachments.
  • Boundary markers: The SKILL.md file contains explicit instructions to treat all evidence as untrusted and never follow embedded instructions to run commands or reveal data.
  • Capability inventory: Execution is limited to jurisdiction lookup and structured generation of Markdown/PDF files; no arbitrary shell command execution or network exfiltration capabilities are exposed to untrusted input.
  • Sanitization: The skill employs url_safety.py for canonical public-HTTPS validation and SSRF protection, and build_appeal_packet.py for strict JSON schema enforcement.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:00 PM
Security Audit — agent-trust-hub — prepare-property-tax-appeal