financeiro-compliance

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for financial and legal analysis within the Brazilian regulatory environment. All components are static markdown files with no executable code, shell commands, or external dependencies.\n- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it instructs the agent to analyze user-provided contracts and financial reports. However, the risk is mitigated by the lack of exploitable capabilities (such as network access or file writing) within the skill itself.\n
  • Ingestion points: Instructions in contratos-br/SKILL.md and dre-balanco/SKILL.md explicitly direct the agent to read and review user-supplied data.\n
  • Boundary markers: None identified; inputs are processed directly without specific delimiters.\n
  • Capability inventory: The skill does not define any functions for file writing, network access, or shell execution.\n
  • Sanitization: None identified.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: No exfiltration patterns, credential leakage, or unauthorized network activity were detected. All analysis is intended to occur within the local session context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:10 AM
Security Audit — agent-trust-hub — financeiro-compliance