catalog-browser
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively utilizes vendor-provided tools (
ZohoBilling_List_all_Products,ZohoBilling_List_all_Plans, etc.) consistent with its author ('zoho'). - [SAFE]: The skill includes explicit constraints such as 'Propose-only: no catalog changes', which prevents unauthorized modifications to the service configuration.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data retrieved from API tools.
- Ingestion points: Product, Plan, Addon, and Item list tool outputs (SKILL.md).
- Boundary markers: None explicitly defined in the output instructions.
- Capability inventory: Limited to read-only retrieval tools; no file-write, network-send (beyond tool calls), or command execution capabilities are present.
- Sanitization: Not explicitly defined, however, the skill's restricted output format (Grouped listing) limits the impact of potential malicious data in the catalog.
Audit Metadata