invoice-organizer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and organizes files using standard shell commands such as find, mkdir, cp, and mv. These operations are limited to the user's local filesystem and align with the skill's stated purpose of file management.
  • [DATA_EXFILTRATION]: No network activity or attempts to access sensitive system files such as credentials, SSH keys, or configuration files were observed.
  • [PROMPT_INJECTION]: The skill processes untrusted content from external files like PDFs and images which creates an indirect prompt injection surface. 1. Ingestion points: File content from invoices and receipts. 2. Boundary markers: Absent; instructions do not specify using delimiters or warnings. 3. Capability inventory: Local file management and command execution. 4. Sanitization: Not explicitly mandated for extracted metadata used in file naming or folder creation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 09:44 PM
Security Audit — agent-trust-hub — invoice-organizer