tax-check

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses pnpm report and pnpm gains to run local scripts for tax calculation and report generation.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external financial records. Ingestion points: Reads data from normalized/capital-gains.json, normalized/w2-data.json, normalized/charitable-donations.json, and reports/tax-ready/form-8949-c.csv. Boundary markers: There are no boundary markers or instructions provided to the agent to treat file content as untrusted data or to ignore embedded instructions. Capability inventory: The skill has command execution capabilities via pnpm and access to sensitive local file paths. Sanitization: There is no evidence of sanitization, escaping, or validation of the content within the financial files before they are interpolated into the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 02:26 PM