pp-zoho-expense
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Installs the
zoho-expense-pp-clitool usingnpxandgo installfrom vendor-controlled repositories. - [COMMAND_EXECUTION]: Executes the CLI binary and installation commands via the shell.
- [CREDENTIALS_UNSAFE]: Stores OAuth 2.0 refresh tokens in a local configuration file at
~/.config/zoho-expense-pp-cli/config.toml. - [DATA_EXFILTRATION]: Allows routing command output to external URLs via a
--deliver webhook:<url>parameter. - [PROMPT_INJECTION]: The skill processes invoices and receipts which are untrusted external data sources. Ingestion points:
invoice ingestandreceipt upload. Boundary markers: None present. Capability inventory: Network access for API calls and webhooks, and local file system access. Sanitization: No content validation is performed on the files.
Audit Metadata