invoice-chase
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources including accounting systems (~~бухгалтерии), payment platforms (~~платежи), and user-uploaded spreadsheets. Although this represents an injection surface, the risk is effectively mitigated by the 'approval gate' architecture, which requires the user to review all generated drafts before they are sent. Evidence chain: 1. Ingestion points include tools for accounting and payments. 2. Boundary markers are absent but the skill follows strict templates. 3. Capability inventory includes sending via mail and messenger tools. 4. Sanitization is not explicitly mentioned, but manual user review serves as a functional filter.
- [DATA_EXFILTRATION]: While the skill accesses sensitive financial data to evaluate client reliability and debt status, it does not perform automated network requests to unauthorized third-party domains. All communication channels are explicitly configured by the user, and no data is sent to clients without explicit manual verification step for each batch.
Audit Metadata