NYC

financial-document-processor

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill processes external financial documents, which serves as a potential ingestion point for malicious instructions. Ingestion points: Text is extracted from PDFs and images using 'pypdf' and 'tesseract' in 'SKILL.md'. Boundary markers: The provided guidance does not include delimiters to isolate untrusted data. Capability inventory: The skill uses file system commands (cp, mv, rm) and package installation (pip, apt-get). Sanitization: Extracted document text is not sanitized before being utilized by the agent logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:47 PM