openaccountants-us-ca

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes specific MCP tools including 'start', 'get_skill', and 'request_accountant_review' to interact with the vendor's tax logic engine. These are standard functional calls for an MCP-based agent skill.
  • [DATA_EXFILTRATION]: When the user triggers a professional review, the skill transmits 'working papers' to the developer's verified domain (openaccountants.com). This behavior is consistent with the stated purpose of routing tax scenarios to human verifiers.
  • [PROMPT_INJECTION]: The instructions include a mandate to prioritize retrieved tax rules over general training data. This is an accuracy-focused directive designed to ensure the agent uses current legislative rates and citations rather than potentially outdated internal knowledge.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 06:54 PM
Security Audit — agent-trust-hub — openaccountants-us-ca