ns-commercial-budget
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill provides a highly structured and restricted workflow for budgeting.
- [PROMPT_INJECTION]: The skill uses instructional language to guide the AI's behavior for its primary task, such as 'Never invent R$' and 'Block sizing without inventory,' which are legitimate constraints rather than malicious injection attempts.
- [DATA_EXFILTRATION]: The skill reads from and writes to the local project's 'docs/' folder to maintain context and versioning. It does not perform network calls or access sensitive system paths (e.g., .ssh, .aws).
- [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic execution patterns were found. Dependencies like 'ns-harness' are internal vendor resources.
Audit Metadata