invoice-template

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (such as item descriptions and notes) to generate invoices, creating a potential surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the skill context through the invoice_data structure, specifically via fields like notes, items, and client details defined in SKILL.md.
  • Boundary markers: There are no specific delimiters or instructions to the agent to ignore embedded commands within the input data.
  • Capability inventory: The skill utilizes MCP tools (create_docx, fill_docx_template, docx_to_pdf) and Python libraries (reportlab, jinja2) to write files to the local system.
  • Sanitization: The instructions focus on validating calculations but do not include patterns for sanitizing or escaping string inputs to prevent injection attacks.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to external resources for documentation and reference.
  • Evidence: References the easy-invoice-pdf repository on GitHub (github.com/nickmitchko/easy-invoice-pdf) and the author's own hub (github.com/claude-office-skills/skills). These are presented as informational resources and are not executed automatically.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:53 PM
Security Audit — agent-trust-hub — invoice-template