runway-calculator
Warn
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to direct the user to add an external MCP server endpoint at https://api.wellapp.ai/v1/mcp. This domain (wellapp.ai) does not strictly match the verified resource patterns associated with the author wellapp-ai (e.g., wellapp-ai.com, wellapp-ai.io), indicating a connection to a potentially unverified external service.\n- [DATA_EXFILTRATION]: Instructions facilitate the transmission of workspace identifiers and financial connector metadata to the external domain api.wellapp.ai.\n- [PROMPT_INJECTION]: The skill ingests data from external financial connectors, creating a vulnerability surface for indirect prompt injection. \n * Ingestion points: Reads data via well_query_records and well_get_runway tools. \n * Boundary markers: Absent; there are no instructions to the agent to treat tool outputs as untrusted or to use delimiters. \n * Capability inventory: Accesses workspace metadata, transaction records, and spend categories. \n * Sanitization: None specified; the skill does not mention validation or filtering of the structured financial data returned by the tools.
Audit Metadata