arr-snapshot
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill utilizes vendor-specific tools (e.g.,
ZohoBilling_Get_ARR_Report) to perform revenue calculations as described. Analysis found no evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external API responses, which represents a standard injection surface for agents processing external information.
- Ingestion points: Tool outputs from Zoho Billing API calls described in
SKILL.md. - Boundary markers: Not present in the instruction text.
- Capability inventory: The skill is limited to data aggregation and display; it includes an explicit 'Propose-only' constraint, preventing any unauthorized write actions or system modifications.
- Sanitization: Not explicitly defined, though the skill logic focuses on numerical data processing which reduces risk.
Audit Metadata