catalog-browser

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exclusively utilizes vendor-provided tools (ZohoBilling_List_all_Products, ZohoBilling_List_all_Plans, etc.) consistent with its author ('zoho').
  • [SAFE]: The skill includes explicit constraints such as 'Propose-only: no catalog changes', which prevents unauthorized modifications to the service configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data retrieved from API tools.
  • Ingestion points: Product, Plan, Addon, and Item list tool outputs (SKILL.md).
  • Boundary markers: None explicitly defined in the output instructions.
  • Capability inventory: Limited to read-only retrieval tools; no file-write, network-send (beyond tool calls), or command execution capabilities are present.
  • Sanitization: Not explicitly defined, however, the skill's restricted output format (Grouped listing) limits the impact of potential malicious data in the catalog.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:18 AM
Security Audit — agent-trust-hub — catalog-browser