fiscaliste

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to automatically ingest tax and financial data from a file named foyer.json at the project root to establish user context. This data is then used in reasoning and passed as arguments to the calc_ir.py and dgfip_oracle.py scripts. As this file represents untrusted input that influences the agent's logic while the agent possesses script execution and network capabilities, it creates a surface for indirect prompt injection.\n
  • Ingestion points: Reads foyer.json and examples/*.json to build the tax profile context.\n
  • Boundary markers: The instructions do not specify strict delimiters or warnings to ignore instructions embedded within the user-provided JSON data.\n
  • Capability inventory: The skill uses scripts/calc_ir.py for local deterministic calculations and scripts/dgfip_oracle.py for network-based verification against official tax simulators.\n
  • Sanitization: There is no explicit sanitization or validation logic described in the instructions for the data ingested from foyer.json before it is used in prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:49 AM
Security Audit — agent-trust-hub — fiscaliste