Back to skill

Security audit

ap-invoice-processing

Security checks for vulnerabilities and agentic risk

Overview

This skill automates invoice intake in a disclosed, human-reviewed way and does not contain executable code or hidden behavior.

Install only for a dedicated AP inbox or label, confirm the AP system forwarding destination, restrict access to the AP log and mailbox, and review early run logs because invoice attachments can contain sensitive vendor, banking, tax, or payment details.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This skill is designed to ingest, extract, log, forward, label, and archive invoice emails and attachments, which commonly contain sensitive financial data, banking details, contact information, and sometimes tax identifiers. Failing to explicitly warn operators about this data handling can lead to deployment into inappropriate mailboxes, insufficient access controls, or forwarding to third-party AP systems without adequate review, increasing the chance of unintended data disclosure or noncompliant processing.

Static analysis

No suspicious patterns detected.