variance-analysis-skill
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The
LICENSE-UPSTREAMfile contains anomalous and suspicious text appended to the end of the standard Apache License. This text includes terms like 'recorded-cams', 'cams-data', and 'input()', which are unrelated to the skill's stated purpose of financial analysis and appear to be a probe for agent capabilities. - Ingestion points: The documentation file
LICENSE-UPSTREAMcontains the malicious strings. - Boundary markers: Absent; the suspicious text is not delimited or marked as non-instructional.
- Capability inventory: The skill itself defines no executable code, though it describes financial formulas.
- Sanitization: No sanitization or filtering is applied to documentation content.
- [NO_CODE]: The skill consists entirely of instructional markdown and license documentation. It does not contain any executable scripts, binary files, or external software dependencies.
Audit Metadata