lov-expense-report
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from invoice images and text. 1. Ingestion points: Invoices are read from images and user text input as described in SKILL.md. 2. Boundary markers: The instructions do not specify the use of delimiters or markers for the processed data, though the 'Confirm with User' step provides a manual safety check. 3. Capability inventory: The skill executes a local script (generate_report.py) and writes Excel files to the local file system. 4. Sanitization: The script uses standard JSON parsing and Excel library calls without dynamic evaluation of input strings.
- [EXTERNAL_DOWNLOADS]: The skill requires openpyxl, a common and well-known library for interacting with Excel files.
- [COMMAND_EXECUTION]: The skill invokes a local Python script (scripts/generate_report.py) to perform its core functionality of report generation.
Audit Metadata