dunning-queue

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate reporting functions for Zoho Billing subscriptions using official API tools. All operations align with the intended business purpose of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (customer names, plan names, and subscription statuses) retrieved via API tools. While this data originates from external sources and could theoretically contain malicious payloads, the skill's capabilities are restricted to displaying formatted text to the user, with no access to high-risk operations like file system modification or network exfiltration.
  • Ingestion points: Output from the ZohoBilling_List_all_Subscriptions tool referenced in SKILL.md.
  • Boundary markers: None present in the output template.
  • Capability inventory: Generating formatted text for user display; no command execution or network capabilities identified.
  • Sanitization: None present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:18 AM
Security Audit — agent-trust-hub — dunning-queue