financial-planning-workflow

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates a workflow where the agent ingests and analyzes external, untrusted client data, creating an indirect prompt injection surface. * Ingestion points: Data gathering phase described in SKILL.md (e.g., tax returns, statements). * Boundary markers: Instructions lack delimiters or guidance to ignore instructions embedded in data. * Capability inventory: Access to Bash, Read, Write, and Edit tools. * Sanitization: No validation or filtering of external input is prescribed.
  • [NO_CODE]: The skill consists exclusively of instructional Markdown and does not include any accompanying scripts or executable files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 06:28 AM