cowork-invoice-chaser

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data such as remittance emails and invoice documents (PDF/.docx). This represents an indirect prompt injection vector where malicious instructions could be embedded in files to manipulate the agent's behavior or reconciliation results.\n
  • Ingestion points: The workflow processes a folder of invoices and payment evidence including bank exports and remittance emails.\n
  • Boundary markers: None identified. The instructions do not specify the use of delimiters or 'ignore' commands when reading external file content.\n
  • Capability inventory: The skill employs tools such as Read, Bash, and Write to perform file system operations based on processed data.\n
  • Sanitization: Absent. There are no instructions provided to sanitize or validate the content of the ingested files before they influence the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:05 PM
Security Audit — agent-trust-hub — cowork-invoice-chaser