invoice-template
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (such as item descriptions and notes) to generate invoices, creating a potential surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the skill context through the
invoice_datastructure, specifically via fields likenotes,items, and client details defined inSKILL.md. - Boundary markers: There are no specific delimiters or instructions to the agent to ignore embedded commands within the input data.
- Capability inventory: The skill utilizes MCP tools (
create_docx,fill_docx_template,docx_to_pdf) and Python libraries (reportlab,jinja2) to write files to the local system. - Sanitization: The instructions focus on validating calculations but do not include patterns for sanitizing or escaping string inputs to prevent injection attacks.
- [EXTERNAL_DOWNLOADS]: The skill provides links to external resources for documentation and reference.
- Evidence: References the
easy-invoice-pdfrepository on GitHub (github.com/nickmitchko/easy-invoice-pdf) and the author's own hub (github.com/claude-office-skills/skills). These are presented as informational resources and are not executed automatically.
Audit Metadata