price-check

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill ingests transaction and product data from external platforms (QuickBooks and PayPal), which could introduce external content into the agent's context.
  • Ingestion points: QuickBooks revenue and cost data, and PayPal gross sales data (SKILL.md).
  • Boundary markers: Absent; there are no clear delimiters or instructions specifying how to treat unusual text structures inside product descriptions or customer fields.
  • Capability inventory: The skill configuration allows access to the Bash, WebFetch, and Read tools, which provide powerful processing capabilities.
  • Sanitization: Absent; there is no explicit instruction to sanitize or filter input retrieved from external integrations before formatting it into the data views.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:26 PM
Security Audit — agent-trust-hub — price-check