financial-insights
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [Authenticated Data Access]: The skill uses the
link-clitool to interact with financial data. It correctly implements an authentication flow that requires explicit user approval through a verification URL before any data can be accessed. This ensures that the agent cannot access private data without the user's consent. - [Least Privilege Architecture]: The instructions emphasize using the minimum necessary 'source actions' (permissions) for each request. For example, it distinguishes between
read_balancesandread_link_transactions, advising the agent to only request what is needed for the specific user query. - [Privacy Controls]: There are explicit guidelines prohibiting the retrieval of unrelated financial data or the exposure of sensitive identifiers such as access tokens, credentials, or full account details. It directs the agent to summarize information rather than provide raw sensitive records.
- [Read-Only Operations]: The skill is designed for informational purposes only. The documentation explicitly states that all commands are read-only and that the agent should not attempt to move money, initiate payments, or modify accounts. It even provides a redirection to a different skill for payment actions, maintaining a clear security boundary.
- [Standard Dependency Management]: The skill utilizes a known CLI tool (
@stripe/link-cli) from a recognized organization, which is a standard pattern for extending agent capabilities with external services.
Audit Metadata