finance-billing-ops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources including Stripe sales records, GitHub repositories, and market research on competitor pricing. This creates an attack surface where malicious content embedded in these external sources could influence agent behavior.
- Ingestion points: The workflow in
SKILL.md(Steps 1 and 3) involves reading live billing data and inspecting code paths in sibling repositories. - Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the processed data.
- Capability inventory: The skill references
github-opsandcustomer-billing-opsinSKILL.md, providing capabilities for reading repository data and performing remediation actions. - Sanitization: No sanitization, validation, or filtering of the external content is specified in the workflow.
Audit Metadata