consumer-billing-refunds
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from external sources. \n
- Ingestion points: The skill reads data from receipts, bank descriptors, app-store histories, and connected emails (SKILL.md). \n
- Boundary markers: The instructions do not define specific delimiters or warnings to isolate external data from the system prompt. \n
- Capability inventory: The agent is granted access to terminal, browser, and email search/read/draft tools (SKILL.md). \n
- Sanitization: The skill provides instructions for selective data extraction (avoiding PII) but lacks specific techniques for filtering or escaping instructions embedded in the external content.\n- [DATA_EXFILTRATION]: The skill accesses sensitive financial information but follows a data minimization policy. It explicitly directs the agent to 'Avoid exposing complete card numbers, home addresses, or irrelevant private receipt details' (SKILL.md).
Audit Metadata