bookkeeping-close

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transaction descriptions from external bank and ledger CSV files which are used to influence agent decisions on categorization and adjusting entries.\n
  • Ingestion points: Bank and ledger CSV files processed via scripts/reconcile.py.\n
  • Boundary markers: Absent. The skill instructions do not provide explicit delimiters or instructions to ignore commands that may be embedded in transaction descriptions.\n
  • Capability inventory: The skill uses scripts/reconcile.py for file operations and is designed to interact with accounting APIs (QuickBooks, Xero, Mercury).\n
  • Sanitization: The norm_desc function in scripts/reconcile.py provides basic normalization by converting descriptions to uppercase and removing non-alphanumeric noise.\n- [COMMAND_EXECUTION]: The skill workflow requires the agent to execute a bundled Python utility (scripts/reconcile.py) to perform data processing and generate reconciliation reports. This execution is part of the skill's primary intended function.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:50 AM
Security Audit — agent-trust-hub — bookkeeping-close