skills/nexu-io/open-design/invoice/Gen Agent Trust Hub

invoice

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is a layout and design template for producing static HTML invoices. It guides the agent on how to structure information like sender/recipient blocks, line items, and payment terms.
  • [NO_CODE]: The provided files consist entirely of Markdown instructions and a static HTML/CSS example. There are no JavaScript components, shell scripts, or backend logic that could perform unauthorized actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user input (e.g., project details, billing items) to generate the invoice content. While this is a data ingestion surface, the output is a static HTML artifact intended for the user's manual review and printing, which does not present a path for automated downstream exploitation.
  • [CREDENTIALS_SAFE]: The example.html file contains dummy financial data, including a mock EIN (87-1234567) and generic bank account details for a fictional 'Sable Studio'. These are clearly intended as placeholders for template demonstration and do not represent the exposure of real sensitive credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:39 PM
Security Audit — agent-trust-hub — invoice