invoice-aging

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes official vendor tools (ZohoBilling_List_all_Organizations, ZohoBilling_List_all_Invoices) to perform data retrieval, which is consistent with the skill's purpose and the vendor's identity.
  • [SAFE]: The skill includes an explicit safety constraint ('Propose-only: no write actions'), which ensures the agent does not perform unauthorized modifications to the user's financial data.
  • [SAFE]: Analysis of the fetch logic and output format shows no signs of data exfiltration to external domains, command injection, or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (invoice status and details). While this constitutes an attack surface for indirect prompt injection, the risk is mitigated by the skill's lack of high-privilege capabilities (no shell access, no network requests to unknown domains, no file writing), making it safe for general use.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:18 AM
Security Audit — agent-trust-hub — invoice-aging