cowork-tax-prep-organizer
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted document content from local directories, creating a surface for indirect prompt injection attacks.\n
- Ingestion points: Local files scanned in
Downloadsand other user-provided folders (SKILL.md).\n - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore commands that may be contained within the analyzed tax documents.\n
- Capability inventory: The agent has access to
Bash,Write,Read,Glob, andGreptools.\n - Sanitization: There is no mention of sanitizing or escaping the content extracted from the documents before processing.\n- [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform file system operations like identifying, copying, and renaming documents. This usage is consistent with the skill's primary purpose of organizing a tax preparation package.
Audit Metadata