expense-breakdown
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external MCP server endpoint (https://api.wellapp.ai/v1/mcp) to fetch financial data. This is the official endpoint for the vendor wellapp-ai and is used as intended for data synchronization.
- [SAFE]: No prompt injection patterns or instructions to bypass safety guidelines were detected.
- [SAFE]: The skill does not attempt to access sensitive local files, such as environment variables, SSH keys, or cloud credentials.
- [SAFE]: No obfuscation techniques, such as Base64-encoded commands or hidden Unicode characters, are present in the skill content.
- [SAFE]: The skill uses a predefined set of MCP tools for data retrieval and does not execute arbitrary shell commands or involve unauthorized privilege escalation.
Audit Metadata