invoice-review-compliance

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes highly restrictive output instructions (e.g., "Do not produce narrative analysis", "Do not ask clarifying questions before producing the documents"). While these are designed to ensure consistent and structured document output (reports and letters), they represent a strict control over the agent's conversational behavior and suppress standard interactive guardrails.
  • [DATA_EXFILTRATION]: The instructions direct the agent to search external repositories, specifically "Google Drive", for sensitive organizational documents like "outside counsel guidelines" and "OCGs". This is a core functional requirement for the skill's invoice review logic and is consistent with the stated purpose of Lawve AI's legal operations tools.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its automated processing of untrusted external content.
  • Ingestion points: Line-item data is extracted from uploaded PDF invoices (SKILL.md, Mode 1).
  • Boundary markers: The instructions do not define explicit delimiters or instructions to ignore potential commands embedded within the invoice text.
  • Capability inventory: The agent uses file ingestion and text extraction to process invoice entries.
  • Sanitization: No explicit sanitization or validation of extracted time-entry descriptions is specified before they are interpolated into reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:33 PM
Security Audit — agent-trust-hub — invoice-review-compliance