unit-economics
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions direct the agent to identify and analyze highly sensitive financial information, including bank statements, merchant processor records, and payroll system data. It also accesses internal application metadata by searching the
~/.claude/projects/directory to record execution telemetry, which involves interacting with the agent's own project state. - [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection as it ingests and analyzes data from multiple untrusted sources such as POS systems, accounting exports, and franchise portals. The instructions provide no boundary markers or delimiters to isolate this data from the prompt and do not specify any sanitization or validation steps for the content of the financial records before it is used to generate a report.
Audit Metadata