handle-saas-billing-cases

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of customer email threads. This is a potential surface for indirect prompt injection where a customer might attempt to trick the agent into performing unauthorized refunds or cancellations. However, this risk is thoroughly mitigated by mandatory "Approval gates" for every financial mutation and a requirement to reconcile evidence across the payment provider, product database, and email thread before proceeding.
  • [DATA_EXFILTRATION]: No patterns for unauthorized data exfiltration or exposure of sensitive credentials were detected. The skill uses established support tools for mailbox operations and verification within a controlled environment.
  • [COMMAND_EXECUTION]: The skill does not contain any suspicious shell commands, script executions, or remote code downloads. All operations are confined to predefined tool-based support workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 08:22 AM
Security Audit — agent-trust-hub — handle-saas-billing-cases