close-month

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection: The skill ingests transaction data from external sources like QuickBooks and various payment processors. Untrusted content within these data streams, such as transaction notes or vendor names, could potentially be used to influence the agent's logic.
  • Evidence Chain for Indirect Injection:
  • Ingestion points: Data is pulled from QuickBooks, Stripe, PayPal, and Square (SKILL.md).
  • Boundary markers: None specified for the ingested data.
  • Capability inventory: The skill uses Bash and WebFetch tools and performs file writing for exports (SKILL.md).
  • Sanitization: No explicit sanitization is described, although a manual triage step is required before final processing.
  • Data Export to External Services: The skill's primary function includes saving financial packets to cloud storage (Google Drive or OneDrive). Users should ensure that the destination paths and permissions for these exports are correctly configured to prevent unauthorized access to sensitive financial records.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:26 PM
Security Audit — agent-trust-hub — close-month