creating-financial-models

Warn

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION] (MEDIUM): The skill presents a significant surface for indirect prompt injection. Ingestion points: Ingests external historical financial statements and user-provided growth/risk assumptions as described in SKILL.md. Boundary markers: Absent; no delimiters or system instructions are defined to prevent the agent from executing commands embedded within financial data. Capability inventory: Operates a Python-based valuation engine (dcf_model.py) and generates Excel workbooks, representing high-impact side effects. Sanitization: No evidence of input validation or content filtering for the data processed by the models.
  • [NO_CODE] (INFO): The documentation explicitly lists 'dcf_model.py' and 'sensitivity_analysis.py' as included scripts, but these files were not provided for analysis, limiting the audit to the descriptive metadata and preventing verification of safe coding practices.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 11:57 PM