expense-management
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No executable code, shell commands, or external scripts are included in the skill. The content consists entirely of instructional markdown and static data schemas.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an ingestion surface for untrusted user input within the expense report fields (e.g., business_purpose, description, and policy_exception_reason). While this represents a theoretical surface for malicious instructions embedded in data, no automated tools or execution capabilities are defined that would allow for exploitation. Ingestion points: expense_report fields in SKILL.md. Boundary markers: Absent. Capability inventory: None. Sanitization: Absent.
Audit Metadata