expansion-opportunities

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses vendor-owned tools (prefixed with ZohoBilling_) to perform read-only analysis of customer subscriptions and usage records. No data is sent to external or non-whitelisted domains, and no system modifications are attempted.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses, creating a theoretical attack surface for indirect prompt injection.
  • Ingestion points: Customer usage data and subscription details are fetched via ZohoBilling tools in the 'Fetch' section of SKILL.md.
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: The skill is limited to read-only reporting and lacks dangerous capabilities such as file system writes, shell execution, or arbitrary network requests.
  • Sanitization: No specific sanitization of API data is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:18 AM
Security Audit — agent-trust-hub — expansion-opportunities