finance-billing-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources including Stripe sales records, GitHub repositories, and market research on competitor pricing. This creates an attack surface where malicious content embedded in these external sources could influence agent behavior.
  • Ingestion points: The workflow in SKILL.md (Steps 1 and 3) involves reading live billing data and inspecting code paths in sibling repositories.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the processed data.
  • Capability inventory: The skill references github-ops and customer-billing-ops in SKILL.md, providing capabilities for reading repository data and performing remediation actions.
  • Sanitization: No sanitization, validation, or filtering of the external content is specified in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — finance-billing-ops