skills/tonone-ai/tonone/mint-runway/Gen Agent Trust Hub

mint-runway

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute find and grep commands. These commands are used to identify local files (Markdown and CSV) containing financial keywords like 'cash', 'burn', and 'payroll' to gather data for analysis. This behavior is consistent with the skill's stated purpose of financial modeling.
  • [DATA_EXPOSURE]: The skill is designed to access and process sensitive financial information such as cash balances, expenses, and payroll data. However, there are no network tools (like curl or wget) enabled in the allowed-tools configuration, and no external domains are referenced, limiting the risk of data exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local files during the search process in Step 0. While this presents a potential surface for indirect prompt injection if a processed file contains malicious instructions, the skill does not possess high-risk capabilities like network access or privilege escalation that would make such an injection critical. No boundary markers or sanitization logic are explicitly defined for the search output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:49 AM
Security Audit — agent-trust-hub — mint-runway