pay-the-bills
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [Indirect Prompt Injection] The skill processes untrusted external data (PDF invoices, phone photos, vendor emails). While the instructions mandate a human approval step ('Gate one') before data is written to a ledger, there is an inherent risk that a maliciously crafted invoice could attempt to influence the agent's extraction or coding logic. This is mitigated by the explicit requirement for owner review.
- [Capability to Expand Toolset] The skill mentions a
build-connectortool to add new integrations via Zapier. While this introduces dynamic behavior, it is explicitly gated by owner request and uses a structured connection path rather than arbitrary code execution. - [Financial Data Handling] The skill handles sensitive financial information (cash flow, bank balances, accounts payable). It implements best practices by requiring two-stage approvals and mandatory cash-flow checks to prevent unauthorized or risky financial operations.
Audit Metadata