Back to skill

Security audit

global-invoicing-research

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed invoice-research/report-writing skill, with only a minor risk that it may trigger too broadly.

Install if you want help researching country-specific invoice requirements and producing reports. Use explicit requests when invoking it, and review any generated document before relying on it for legal, tax, or compliance decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill forces invocation for broadly defined requests such as any mention of country invoice research, even when the user may only want a brief answer or a different workflow. Overly broad mandatory triggering can cause inappropriate tool routing, unnecessary file generation, and reduced user control, which is a genuine security and safety concern in agent systems because it expands the skill’s authority beyond clearly scoped intent.

Static analysis

No suspicious patterns detected.