finance-based-pricing-advisor

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of natural language instructions and logic for interactive consultation. It does not perform any network requests, command executions, or file system operations.- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for untrusted user input as it asks for financial metrics and business context in multiple stages.
  • Ingestion points: User-provided text in Step 0 (Gather Context), Step 2 (Assess Impact), and Step 3 (Evaluate Current State).
  • Boundary markers: The skill does not define explicit delimiters for user-provided data.
  • Capability inventory: The skill has no capabilities beyond text generation (no subprocesses, no file-writing, no network access).
  • Sanitization: None, as the output is restricted to natural language dialogue.
  • Assessment: Because the skill lacks any privileged tools or automated actions, the risk of instruction overriding is minimal and contained to the chat interface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:40 PM
Security Audit — agent-trust-hub — finance-based-pricing-advisor