card-expiry-detector

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes subscription and customer data from Zoho Billing, which constitutes an ingestion surface for untrusted external data. However, the risk is minimal as the skill is explicitly limited to 'propose-only' output for human review and possesses no capabilities for command execution, file modification, or network exfiltration.
  • [DATA_EXPOSURE]: The skill accesses billing-related metadata including subscription numbers, customer identifiers, and the last four digits of payment cards. This behavior is consistent with its stated purpose of managing payment method health and does not involve the exposure of full sensitive credentials or PII beyond what is required for the task.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:18 AM
Security Audit — agent-trust-hub — card-expiry-detector