reconciliation
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface due to the ingestion of untrusted data and its file-system write capabilities.\n
- Ingestion points: The skill ingests untrusted data from external financial platforms (e.g., BlackLine, Trintech) and ERP systems (e.g., SAP, Oracle) as described in Phase 1 through Phase 6.\n
- Boundary markers: The instructions do not define boundary markers or delimiters for the untrusted data, nor do they instruct the agent to ignore instructions that may be embedded in that data.\n
- Capability inventory: The skill includes capabilities to write analysis reports to
docs/reconciliation-analysis.mdand append telemetry metadata to~/.claude/projects/skill-telemetry.md.\n - Sanitization: The skill lacks routines for sanitizing, validating, or escaping the external financial content before it is incorporated into the agent's context or output files.
Audit Metadata