creating-financial-models
Warn
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: MEDIUMPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION] (MEDIUM): The skill presents a significant surface for indirect prompt injection. Ingestion points: Ingests external historical financial statements and user-provided growth/risk assumptions as described in SKILL.md. Boundary markers: Absent; no delimiters or system instructions are defined to prevent the agent from executing commands embedded within financial data. Capability inventory: Operates a Python-based valuation engine (dcf_model.py) and generates Excel workbooks, representing high-impact side effects. Sanitization: No evidence of input validation or content filtering for the data processed by the models.
- [NO_CODE] (INFO): The documentation explicitly lists 'dcf_model.py' and 'sensitivity_analysis.py' as included scripts, but these files were not provided for analysis, limiting the audit to the descriptive metadata and preventing verification of safe coding practices.
Audit Metadata