skills/vm0-ai/vm0-skills/finicity/Gen Agent Trust Hub

finicity

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the okou CLI tool and jq via shell commands to interact with banking data.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is designed to access and display sensitive financial information, including account balances and detailed transaction histories.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests transaction descriptions and merchant names from external banking records, which provides an attack surface for indirect prompt injection.
  • Ingestion points: Bank transaction details retrieved using okou banking transactions in SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or warnings to treat the retrieved financial data as untrusted text.
  • Capability inventory: The skill has the ability to execute shell commands via the okou CLI as seen in SKILL.md.
  • Sanitization: No sanitization, escaping, or filtering of the external transaction content is specified before the agent processes the information.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 02:56 PM
Security Audit — agent-trust-hub — finicity