lov-expense-report

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from invoice images and text. 1. Ingestion points: Invoices are read from images and user text input as described in SKILL.md. 2. Boundary markers: The instructions do not specify the use of delimiters or markers for the processed data, though the 'Confirm with User' step provides a manual safety check. 3. Capability inventory: The skill executes a local script (generate_report.py) and writes Excel files to the local file system. 4. Sanitization: The script uses standard JSON parsing and Excel library calls without dynamic evaluation of input strings.
  • [EXTERNAL_DOWNLOADS]: The skill requires openpyxl, a common and well-known library for interacting with Excel files.
  • [COMMAND_EXECUTION]: The skill invokes a local Python script (scripts/generate_report.py) to perform its core functionality of report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 07:35 AM
Security Audit — agent-trust-hub — lov-expense-report