lov-expense-report
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified in the skill's scripts or instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of invoice images and text descriptions.
- Ingestion points: Invoice photos and user-provided text as described in the workflow in SKILL.md.
- Boundary markers: The workflow includes a mandatory Step 3 where the agent must present a table of extracted data and use AskUserQuestion to obtain user confirmation before proceeding.
- Capability inventory: The local script scripts/generate_report.py performs file system writes to create the Excel (.xlsx) output.
- Sanitization: Data is handled through standard JSON parsing and openpyxl library methods, which prevents direct execution of input data during the report generation process.
Audit Metadata