openaccountants-us-ma

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches tax logic and authoritative rules from the vendor's MCP server at https://www.openaccountants.com/api/mcp. This mechanism ensures the agent uses current accounting standards.
  • [DATA_EXFILTRATION]: Transmits user-provided data, including tax scenarios and working papers, to the vendor's infrastructure when the request_accountant_review tool is invoked.
  • [PROMPT_INJECTION]: The skill utilizes instructions dynamically loaded at runtime from the OpenAccountants API.
  • Ingestion points: Markdown content returned by the get_skill tool as described in SKILL.md.
  • Boundary markers: No explicit delimiters or warnings are used to isolate the loaded content.
  • Capability inventory: Interaction with the openaccountants MCP server tools (start, get_skill, request_accountant_review).
  • Sanitization: The skill relies on the authority of the vendor's API for the safety of the returned markdown content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:12 AM
Security Audit — agent-trust-hub — openaccountants-us-ma