business-case

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides Python code snippets in rules/business-roi.md for calculating NPV and IRR metrics using the scipy library. These snippets are presented as static reference code for the agent to perform precise calculations.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines templates that ingest user-defined strings for project names and financial descriptions. Ingestion points: Template placeholders in SKILL.md and rules/business-cost-benefit.md. Boundary markers: Markdown headers and table structures. Capability inventory: File system tools (Read, Glob, Grep) and network tools (WebFetch, WebSearch). Sanitization: No explicit sanitization or instruction-ignoring delimiters are defined in the templates. This represents a standard surface for indirect prompt injection common in document-generation skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 AM
Security Audit — agent-trust-hub — business-case