pp-zoho-expense

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the zoho-expense-pp-cli tool using npx and go install from vendor-controlled repositories.
  • [COMMAND_EXECUTION]: Executes the CLI binary and installation commands via the shell.
  • [CREDENTIALS_UNSAFE]: Stores OAuth 2.0 refresh tokens in a local configuration file at ~/.config/zoho-expense-pp-cli/config.toml.
  • [DATA_EXFILTRATION]: Allows routing command output to external URLs via a --deliver webhook:<url> parameter.
  • [PROMPT_INJECTION]: The skill processes invoices and receipts which are untrusted external data sources. Ingestion points: invoice ingest and receipt upload. Boundary markers: None present. Capability inventory: Network access for API calls and webhooks, and local file system access. Sanitization: No content validation is performed on the files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 04:05 AM
Security Audit — agent-trust-hub — pp-zoho-expense