invoice-aging
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes official vendor tools (
ZohoBilling_List_all_Organizations,ZohoBilling_List_all_Invoices) to perform data retrieval, which is consistent with the skill's purpose and the vendor's identity. - [SAFE]: The skill includes an explicit safety constraint ('Propose-only: no write actions'), which ensures the agent does not perform unauthorized modifications to the user's financial data.
- [SAFE]: Analysis of the fetch logic and output format shows no signs of data exfiltration to external domains, command injection, or persistence mechanisms.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (invoice status and details). While this constitutes an attack surface for indirect prompt injection, the risk is mitigated by the skill's lack of high-privilege capabilities (no shell access, no network requests to unknown domains, no file writing), making it safe for general use.
Audit Metadata