report-ai-bookkeeping
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script
bookkeeping.pyto generate reports from confirmed transaction data. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads personal financial records to perform consumption analysis. Risk is mitigated by instructions requiring the generated HTML to be self-contained and offline, with no external scripts or images.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect injection by processing external transaction descriptions. 1. Ingestion points: Reads transaction flow data. 2. Boundary markers: Absent. 3. Capability inventory: Script execution and file writing. 4. Sanitization: Mandates offline HTML without external resources.
Audit Metadata