finance-budget

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to provide budgeting advice and generate reports. All operations described, such as data categorization and benchmarking, are consistent with this purpose. No malicious commands or scripts are included.
  • [DATA_EXPOSURE]: The skill prompts the user to input sensitive personal financial information, including net income, debt minimums, and detailed spending habits. While this is necessary for its stated function, it results in sensitive data entering the agent's context. No network exfiltration or hardcoded credentials were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it ingests untrusted user input and uses it to generate a local file.
  • Ingestion points: The agent asks the user for income, expense, and debt data as defined in the 'Data Collection' section of SKILL.md.
  • Boundary markers: None are specified for the ingested data.
  • Capability inventory: The skill uses the agent's file-writing capability to create FINANCE-BUDGET.md.
  • Sanitization: No explicit sanitization or validation of the user-provided data is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 04:45 PM
Security Audit — agent-trust-hub — finance-budget