payment-failure-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions involve processing untrusted gateway error messages (e.g., from Stripe or PayPal) within payment failure records.
  • Ingestion points: Payment failure records from Zoho Billing as described in SKILL.md.
  • Boundary markers: No delimiters or instructions are specified to prevent the agent from following potential commands embedded in the external gateway data.
  • Capability inventory: Data analysis, categorization, and strategy recommendation; the skill explicitly states it does not perform automated actions (payments, refunds, or notifications) and has no associated code tools.
  • Sanitization: No sanitization or validation methods for external failure messages are described.
  • [NO_CODE]: The skill consists of a single markdown file (SKILL.md) providing instructions and metadata, and does not include any executable scripts, binaries, or active tool configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:18 AM
Security Audit — agent-trust-hub — payment-failure-analyzer