pay-the-bills

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection] The skill processes untrusted external data (PDF invoices, phone photos, vendor emails). While the instructions mandate a human approval step ('Gate one') before data is written to a ledger, there is an inherent risk that a maliciously crafted invoice could attempt to influence the agent's extraction or coding logic. This is mitigated by the explicit requirement for owner review.
  • [Capability to Expand Toolset] The skill mentions a build-connector tool to add new integrations via Zapier. While this introduces dynamic behavior, it is explicitly gated by owner request and uses a structured connection path rather than arbitrary code execution.
  • [Financial Data Handling] The skill handles sensitive financial information (cash flow, bank balances, accounts payable). It implements best practices by requiring two-stage approvals and mandatory cash-flow checks to prevent unauthorized or risky financial operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:05 PM
Security Audit — agent-trust-hub — pay-the-bills