cowork-invoice-chaser
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data such as remittance emails and invoice documents (PDF/.docx). This represents an indirect prompt injection vector where malicious instructions could be embedded in files to manipulate the agent's behavior or reconciliation results.\n
- Ingestion points: The workflow processes a folder of invoices and payment evidence including bank exports and remittance emails.\n
- Boundary markers: None identified. The instructions do not specify the use of delimiters or 'ignore' commands when reading external file content.\n
- Capability inventory: The skill employs tools such as
Read,Bash, andWriteto perform file system operations based on processed data.\n - Sanitization: Absent. There are no instructions provided to sanitize or validate the content of the ingested files before they influence the agent's logic.
Audit Metadata