finop-recon
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface detected in the data gathering phase.
- Ingestion points: Processes output from external FinOps tools (AWS Cost Explorer, CloudHealth, Infracost) and user-supplied context as described in
SKILL.md. - Boundary markers: Absent; the instructions do not specify the use of delimiters or instructions to ignore embedded commands for external data processing.
- Capability inventory: The skill has access to
Bashfor command execution andWebFetch/WebSearchfor network access, creating a potential path for data-driven attacks if processed content is malicious. - Sanitization: Absent; no evidence of data validation or escaping is present in the provided instructions.
Audit Metadata