billing-behaviors
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown documentation and logic guidelines for an AI agent to follow. There are no scripts, binaries, or automation files included that could execute arbitrary commands.
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions on how to interpret billing data, which is an ingestion point for external information. However, the instructions specifically mitigate risks by requiring the agent to verify persisted database state (e.g., 'persisted deadline', 'exact stored timestamp') rather than user-facing dashboard values, which prevents simple data-driven manipulation.
- [SAFE]: All referenced domains (commet.co) and repositories (github.com/commet-labs) are verified resources belonging to the skill's author, commet-labs. The skill promotes best practices for security and reliability, such as using stable idempotency keys for billing operations.
Audit Metadata