bookkeeping-close
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transaction descriptions from external bank and ledger CSV files which are used to influence agent decisions on categorization and adjusting entries.\n
- Ingestion points: Bank and ledger CSV files processed via
scripts/reconcile.py.\n - Boundary markers: Absent. The skill instructions do not provide explicit delimiters or instructions to ignore commands that may be embedded in transaction descriptions.\n
- Capability inventory: The skill uses
scripts/reconcile.pyfor file operations and is designed to interact with accounting APIs (QuickBooks, Xero, Mercury).\n - Sanitization: The
norm_descfunction inscripts/reconcile.pyprovides basic normalization by converting descriptions to uppercase and removing non-alphanumeric noise.\n- [COMMAND_EXECUTION]: The skill workflow requires the agent to execute a bundled Python utility (scripts/reconcile.py) to perform data processing and generate reconciliation reports. This execution is part of the skill's primary intended function.
Audit Metadata