comptable

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches accounting data, specifically the French Plan Comptable Général (PCG), from a community repository (github.com/arrhes/PCG) and tax nomenclature from the official data.gouv.fr platform. These downloads are performed to ensure the tool uses up-to-date regulatory frameworks.
  • [COMMAND_EXECUTION]: The skill executes local Python and Node.js scripts to automate financial workflows such as VAT calculation, generation of mandatory accounting files (FEC), and creation of Factur-X compliant invoices. These scripts operate within the project's local directory scope.
  • [DATA_EXFILTRATION]: The skill is designed to synchronize invoice documents and transaction metadata with the Qonto and Stripe platforms. While this involves transferring sensitive financial information, the destinations are established financial service providers, and the operations are essential to the skill's primary function of automated bank reconciliation and invoice management.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes externally sourced data including bank transaction labels and invoice details provided by third parties. While this ingests potentially untrusted content into the agent's context, the skill mitigates this risk through explicit instructions requiring the agent to verify all conseil against validated context and to follow conservative accounting principles.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:49 AM
Security Audit — agent-trust-hub — comptable