cowork-tax-prep-organizer

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted document content from local directories, creating a surface for indirect prompt injection attacks.\n
  • Ingestion points: Local files scanned in Downloads and other user-provided folders (SKILL.md).\n
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore commands that may be contained within the analyzed tax documents.\n
  • Capability inventory: The agent has access to Bash, Write, Read, Glob, and Grep tools.\n
  • Sanitization: There is no mention of sanitizing or escaping the content extracted from the documents before processing.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to perform file system operations like identifying, copying, and renaming documents. This usage is consistent with the skill's primary purpose of organizing a tax preparation package.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:05 PM
Security Audit — agent-trust-hub — cowork-tax-prep-organizer