cash-balance-trend

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to the vendor-owned endpoint at https://api.wellapp.ai/v1/mcp to fetch financial data. This is an expected behavior for a skill authored by wellapp-ai to interact with its own MCP server.
  • [DATA_EXFILTRATION]: The skill accesses sensitive financial information such as account balances and schemas; however, this data is only used to generate the requested historical trend reports for the user and is not sent to unauthorized third-party domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external financial records through well_query_records. Although this provides a surface for indirect injection, the skill's workflow is limited to data retrieval and table/chart formatting, which does not grant the agent high-privilege capabilities that could be exploited by malicious data content.
  • [COMMAND_EXECUTION]: No evidence of unauthorized shell command execution, script generation, or system-level access was found. The skill operates within the boundaries of the provided MCP tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:26 AM
Security Audit — agent-trust-hub — cash-balance-trend