skills/rohitg00/buildwithclaude/tidy/Gen Agent Trust Hub

tidy

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted transaction descriptions and email content, which creates a surface for indirect prompt injection.\n- Ingestion points: Transaction data is fetched via the query tool, and user emails are accessed via search functionality.\n- Boundary markers: No specific delimiters are defined in the instructions to isolate external transaction data from the agent's internal logic.\n- Capability inventory: The skill can modify financial categories and create persistent automation rules via the admin tool.\n- Sanitization: There is no mention of sanitizing or escaping external strings before processing.\n- Mitigation: A mandatory human-in-the-loop step requires the user to approve, modify, or skip each suggested cluster before any actions are taken.\n- [DATA_EXFILTRATION]: Merchant names, phone numbers, and domains from transaction descriptions are sent to external web search engines and email providers to identify businesses. This data transmission is a functional requirement for the transaction research process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — tidy