Back to skill

Security audit

Invoice Management Faq

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward invoice-process FAQ with no evidence of hidden behavior, credential use, persistence, network access, or data mutation.

Installers should treat this as an internal invoice-policy reference, not as a live finance system. Verify the bundled FAQ matches current company policy before relying on it, especially because the skill instructs agents not to modify the source answer text.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are generic invoice-related terms that can match ordinary conversation without a clear boundary for when the skill should activate. This can cause unintended invocation and make the agent answer from a rigid FAQ in contexts where a broader, more accurate, or policy-aware response is needed.

Static analysis

No suspicious patterns detected.