skills/simota/agent-skills/ledger/Gen Agent Trust Hub

ledger

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and reference materials focus entirely on financial operations and cost management for cloud environments. No malicious commands or scripts were identified across the 15 analyzed files.
  • [REMOTE_CODE_EXECUTION]: No suspicious remote code execution patterns were found. References to the 'Infracost' tool are standard industry practice for IaC cost estimation and do not involve piped remote execution from unknown sources.
  • [DATA_EXFILTRATION]: No patterns for exfiltrating sensitive data were detected. The skill uses standard cloud provider pricing APIs and well-known technical reference sites for data.
  • [OBFUSCATION]: No obfuscated strings, multi-layer Base64, zero-width characters, or homoglyph attacks were found in the skill content.
  • [PROMPT_INJECTION]: The skill instructions do not contain attempts to override safety filters or bypass system prompts.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (IaC code and utilization metrics) to generate reports, it lacks dangerous execution capabilities that could be exploited via indirect injection. The risk surface is minimal and handled through structured analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — ledger