cowork-expense-audit

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's primary function is local file processing (receipts, statements) and data reconciliation. All operations are confined to the user-provided directory.
  • [PROMPT_INJECTION]: The skill exhibits an inherent surface for indirect prompt injection as it processes untrusted external data (receipts and statements). Malicious content within these files could attempt to influence agent behavior during extraction. 1. Ingestion points: Directory of receipts (PDF, images) and statements (.csv, .xlsx) processed in the inventory and extraction steps. 2. Boundary markers: Absent; the instructions do not specify delimiters to separate untrusted file content from system instructions. 3. Capability inventory: The skill uses Read, Glob, Grep, Write, and Bash tools. 4. Sanitization: No sanitization or validation of the extracted transaction text is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:05 PM
Security Audit — agent-trust-hub — cowork-expense-audit