collections-today
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes official vendor tools (
ZohoBilling_Get_AR_Aging_Details_Report,ZohoBilling_Get_Time_to_Pay_Report,ZohoBilling_Get_Customer_Payments_Report,ZohoBilling_Get_Customer_Balance_Summary_Report) to retrieve accounts receivable data. The use of these tools is consistent with the skill's stated purpose and the identified author (zoho). - [SAFE]: A safety constraint is explicitly defined ("Propose-only: no emails sent, no payments applied"), which prevents the agent from performing automated financial transactions or communications without user intervention.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Zoho Billing reports, which constitutes an ingestion surface for potentially untrusted content (e.g., customer names or invoice descriptions). However, the skill lacks high-privilege capabilities such as shell execution, arbitrary file writes, or unrestricted network operations that would allow such an injection to be exploited.
- [SAFE]: No obfuscation, hardcoded credentials, or persistence mechanisms were detected in the skill instructions or reference files.
Audit Metadata