Back to skill

Security audit

Zoho Books

Security checks across malware telemetry and agentic risk

Overview

This Zoho Books skill is a disclosed accounting integration, but users should be careful with write permissions because it can change, delete, void, email, and reconcile financial records.

Install only if you intend to let an agent work with Zoho Books through AgentPMT. Start with read-only access, grant add/edit/delete permissions only when needed, and manually confirm the organization, record ID, recipient, and requested change before allowing invoice emails, voids, deletes, bank matching, or other accounting writes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents destructive and externally visible accounting actions such as deleting invoices, voiding invoices, emailing invoices, and matching bank transactions, but it does not instruct the agent to obtain explicit user confirmation before performing them. In an agent setting, this increases the risk of accidental financial changes or customer-facing actions being executed from ambiguous prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.