financial-parser
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from invoices, receipts, and bank statements provided by users as PDFs or images. This creates a surface for indirect prompt injection where malicious instructions embedded in the documents could attempt to influence the agent's output or logic.
- Ingestion points: User-provided financial documents (PDFs and images) mentioned in
SKILL.mdunder the 'When to Use' and 'Instructions' sections. - Boundary markers: Absent. The instructions do not define clear delimiters or specific directives for the agent to ignore instructions found within the document data.
- Capability inventory: None. The skill consists only of instructions and does not define shell commands, network access, or file system write capabilities within its own scope.
- Sanitization: Absent. The skill lacks mechanisms to sanitize or validate the content of the documents being parsed beyond recommending masking the last 4 digits of account numbers.
- [NO_CODE]: The skill contains no executable scripts, binaries, or configuration files that initiate code execution. It relies entirely on natural language instructions to guide the agent's behavior when processing documents.
Audit Metadata