reconciliation

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface due to the ingestion of untrusted data and its file-system write capabilities.\n
  • Ingestion points: The skill ingests untrusted data from external financial platforms (e.g., BlackLine, Trintech) and ERP systems (e.g., SAP, Oracle) as described in Phase 1 through Phase 6.\n
  • Boundary markers: The instructions do not define boundary markers or delimiters for the untrusted data, nor do they instruct the agent to ignore instructions that may be embedded in that data.\n
  • Capability inventory: The skill includes capabilities to write analysis reports to docs/reconciliation-analysis.md and append telemetry metadata to ~/.claude/projects/skill-telemetry.md.\n
  • Sanitization: The skill lacks routines for sanitizing, validating, or escaping the external financial content before it is incorporated into the agent's context or output files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — reconciliation