ap-processor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- Human-in-the-Loop Controls: The skill strictly enforces manual approval gates for both staging entries in accounting ledgers and proposing payment runs, ensuring no financial actions are taken autonomously.
- Indirect Prompt Injection Mitigations: While the skill processes untrusted external data (such as email bodies and attachments), it includes explicit instructions to treat this content strictly as data rather than commands. The instructions specifically mandate ignoring instructions found within processed data and reference dedicated safety protocols for handling untrusted content.
- Ingestion points: The skill reads from email inboxes (Gmail/Microsoft 365), uploaded PDFs, and photographed invoices.
- Boundary markers: Present. The skill instructs the agent to treat sender messages as data only and specifically flags remit-to changes for manual verification.
- Capability inventory: The skill can stage bills and expenses in NetSuite, QuickBooks, Xero, and Zoho Books, and can draft vendor emails.
- Sanitization: All ledger writes and payments require explicit human approval; bank and card details are masked to the last four digits.
- Data Privacy and PII Masking: The skill follows best practices for handling sensitive financial information by limiting the display of bank and card numbers to the last four digits and the bank name in all outputs.
- Financial Integrity Protections: Built-in logic for deduplication and three-way matching (matching bills against purchase orders and receiving tickets) serves as a safeguard against overpayment and duplicate billing errors.
Audit Metadata