variance-analysis-skill

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The LICENSE-UPSTREAM file contains anomalous and suspicious text appended to the end of the standard Apache License. This text includes terms like 'recorded-cams', 'cams-data', and 'input()', which are unrelated to the skill's stated purpose of financial analysis and appear to be a probe for agent capabilities.
  • Ingestion points: The documentation file LICENSE-UPSTREAM contains the malicious strings.
  • Boundary markers: Absent; the suspicious text is not delimited or marked as non-instructional.
  • Capability inventory: The skill itself defines no executable code, though it describes financial formulas.
  • Sanitization: No sanitization or filtering is applied to documentation content.
  • [NO_CODE]: The skill consists entirely of instructional markdown and license documentation. It does not contain any executable scripts, binary files, or external software dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 11:32 AM
Security Audit — agent-trust-hub — variance-analysis-skill