invoice-generator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input which could contain malicious instructions designed to influence the agent's behavior during document generation.
- Ingestion points: User-provided text for
client_infoandline_itemsfields as defined in theSKILL.mdfrontmatter. - Boundary markers: The instructions do not define clear delimiters or use "ignore embedded instructions" warnings when processing the input data.
- Capability inventory: The skill utilizes several capabilities including
create_docx,fill_docx_template,docx_to_pdf, andcreate_xlsxto generate and manipulate office documents. - Sanitization: No input validation, filtering, or escaping logic is described for the external content before it is interpolated into the final document templates.
Audit Metadata