variance-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • Instructional Guidelines: The skill serves as a knowledge base, providing methodologies and formulas for financial decomposition (e.g., Price/Volume, Rate/Mix). It is purely informational and does not include any executable scripts or tool invocations.
  • No Sensitive Resource Access: The skill does not request access to the network, the file system, or environment variables. It lacks any patterns associated with data exfiltration or credential harvesting.
  • Absence of Obfuscation: The content is written in clear, standard markdown. No hidden characters, encoded strings, or homoglyph substitutions were detected during the analysis.
  • Indirect Prompt Injection Surface: The skill processes user-supplied financial data. Analysis of this surface follows:
  • Ingestion points: Financial line items and drivers provided for analysis via the user prompt.
  • Boundary markers: Not explicitly defined in the skill instructions.
  • Capability inventory: No dangerous capabilities (network, file-system, or process execution) are present in the skill.
  • Sanitization: None identified, but the lack of system-level capabilities renders this surface low-risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:27 PM
Security Audit — agent-trust-hub — variance-analysis