cash-position
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill connects to a remote Model Context Protocol (MCP) server at
https://api.wellapp.ai/v1/mcpto fetch financial data. This infrastructure is owned by the vendor and is necessary for the skill's operation. - [DATA_EXFILTRATION]: The skill accesses sensitive financial information, such as bank account names and balances. This access is limited to authorized vendor tools and is the primary functionality requested by the user.
- [PROMPT_INJECTION]: The skill provides instructions for the agent to handle authentication retries and synchronization checks autonomously (e.g., "don't wait to be re-prompted"). These instructions are designed to improve user experience rather than bypass safety constraints.
- [PROMPT_INJECTION]: A potential indirect prompt injection surface exists where the skill processes data from external bank accounts (account names and sync hints). However, the agent's limited toolset (financial reporting) prevents exploitation for high-risk actions.
- Ingestion points:
well_get_cash_positionandworkspace_connectorstool outputs (SKILL.md). - Boundary markers: Absent.
- Capability inventory: Read-only financial tools (
well_list_workspaces,well_get_cash_position,well_query_records,well_get_schema,well_list_connectors) (SKILL.md). - Sanitization: Not specified.
Audit Metadata