rillet

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill handles third-party accounting data from Rillet, creating a surface for indirect prompt injection.
  • Ingestion points: Fetches invoices, bills, payments, and other financial entities from the Rillet API via the Apideck unified interface.
  • Boundary markers: No specific delimiters or safety instructions are used to distinguish external data from agent instructions.
  • Capability inventory: The skill utilizes the Apideck SDK to perform CRUD operations on accounting records and financial reports.
  • Sanitization: No explicit data sanitization or validation steps are outlined for retrieved content.
  • [EXTERNAL_DOWNLOADS]: The skill references official API specifications and documentation from established domains including apideck.com and rillet.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 05:59 PM
Security Audit — agent-trust-hub — rillet