expansion-opportunities
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses vendor-owned tools (prefixed with ZohoBilling_) to perform read-only analysis of customer subscriptions and usage records. No data is sent to external or non-whitelisted domains, and no system modifications are attempted.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses, creating a theoretical attack surface for indirect prompt injection.
- Ingestion points: Customer usage data and subscription details are fetched via ZohoBilling tools in the 'Fetch' section of SKILL.md.
- Boundary markers: None identified in the prompt templates.
- Capability inventory: The skill is limited to read-only reporting and lacks dangerous capabilities such as file system writes, shell execution, or arbitrary network requests.
- Sanitization: No specific sanitization of API data is documented.
Audit Metadata