tax-prep

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] The skill is designed to ingest and process data from external sources such as bank transactions, QuickBooks, PayPal, and Stripe. This creates a surface for indirect prompt injection, where malicious instructions hidden in transaction descriptions or vendor names could theoretically influence the agent's behavior during processing.
  • [Data Sensitivity] The skill's primary function involves handling highly sensitive financial information, including income, deductions, and contractor payment details. While no exfiltration patterns were detected, the processing of this data requires a trusted environment.
  • [Tool Capability] The skill is configured with access to powerful tools including Bash and WebFetch. Although the instructions do not contain explicit shell commands or suspicious URLs, these capabilities increase the potential impact if the agent were to be influenced by malicious external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:03 AM
Security Audit — agent-trust-hub — tax-prep