adapty-attribution

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides logic to ensure the adapty CLI package is installed, including globally via npm or executed remotely via npx. These are standard methods for accessing the official Adapty CLI provided by the vendor.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the adapty CLI for read-only reporting tasks, such as fetching metrics, dimensions, and values for campaigns and channels.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data returned from external CLI commands, which includes strings defined by users or ad networks (e.g., campaign names, channel names).
  • Ingestion points: Data from adapty attribution report and adapty attribution values commands in references/playbooks.md.
  • Boundary markers: The AI is instructed to parse JSON output, but there are no specific delimiters to prevent the agent from interpreting text within data fields as instructions.
  • Capability inventory: The skill uses bash command execution to interact with the Adapty API.
  • Sanitization: There is no explicit sanitization step for the data received from the CLI before it is presented to the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 05:17 PM
Security Audit — agent-trust-hub — adapty-attribution