tres-invoice-bill-matching

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • Secure Financial Workflow: The skill implements a 'read-before-write' policy and requires explicit user consent for every mutation (matching, fiat alignment, and ERP syncing). This ensures the user maintains full control over financial record changes.
  • Authentication Verification: The process begins with a mandatory identity check using get_viewer, confirming the organization context before displaying or modifying any data.
  • Data Handling: While the skill processes financial information from external ERP systems, it uses these details strictly within the context of the user-initiated reconciliation workflow. All external links point to the official platform domain.
  • Indirect Input Considerations: The skill ingests transaction and invoice data from external sources (ERP systems and blockchain). While this represents a potential surface for indirect content, the skill's requirement for manual user confirmation of all suggested matches and the use of structured GraphQL variables for mutations serve as effective controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 04:44 AM
Security Audit — agent-trust-hub — tres-invoice-bill-matching