tear-sheet

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution: The skill employs shell commands to initialize a local directory for temporary data storage. This practice helps maintain data integrity by using files as a single source of truth during the report generation process.
  • Dynamic Code Execution: The skill guides the agent in generating and executing JavaScript code to produce formatted Word documents. This enables the agent to apply complex styling rules that are difficult to achieve through plain text alone.
  • Processing External Content: The skill is designed to ingest and synthesize financial data and transcripts from external providers. This functionality introduces a potential surface for indirect prompt injection, which is a common characteristic of agents performing research and summarization tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:26 PM
Security Audit — agent-trust-hub — tear-sheet