revenue-recognition-health

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses official Zoho Billing reporting tools (ZohoBilling_Get_*_Report) to gather financial data, which is appropriate for its stated purpose as a revenue health monitor.
  • [SAFE]: The instructions explicitly restrict the agent's capabilities to 'notify-only' and 'propose-only' status, providing a clear prohibition against making journal entries or changing revenue schedules, which ensures a secure read-only posture.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Zoho Billing reports, creating a theoretical ingestion surface for indirect instructions. This is assessed as safe because the skill lacks any capabilities to execute commands, access sensitive system files, or exfiltrate data. (1) Ingestion points: Financial data fetched via Zoho Billing report tools in SKILL.md. (2) Boundary markers: The skill uses a structured markdown template for reports but does not define explicit delimiters for untrusted data. (3) Capability inventory: Restricted to data fetching and output formatting; no subprocess, file-write, or network exfiltration tools are used. (4) Sanitization: The skill does not perform explicit sanitization of the fetched report data before interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:18 AM
Security Audit — agent-trust-hub — revenue-recognition-health