purchase-testing

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the official adapty CLI package globally using the Node Package Manager (NPM). This tool is essential for the skill's diagnostic capabilities and is sourced from a well-known public registry.\n
  • Evidence: npm i -g adapty@latest in SKILL.md.\n- [COMMAND_EXECUTION]: The skill performs multiple shell command executions to interface with the Adapty API via its CLI tool. These commands retrieve metadata about app placements, products, and access levels to diagnose purchase failures.\n
  • Evidence: Commands such as $ADAPTY auth whoami, $ADAPTY placements list, and $ADAPTY flows config get are found in SKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically the output of CLI commands and application code, to analyze and report findings to the user. This represents an attack surface where malicious instructions could be embedded in the data being processed.\n
  • Ingestion points: Output of adapty CLI commands and project source code (via grep) in SKILL.md.\n
  • Boundary markers: The instructions direct the agent to report findings in a specific "short block," providing some logical separation, but no explicit delimiters or "ignore instructions" markers are defined for the external data.\n
  • Capability inventory: File reading (grep), shell command execution (adapty CLI), and network operations (via the CLI tool) in SKILL.md.\n
  • Sanitization: No explicit sanitization, validation, or escaping of the CLI output or code contents is performed before the agent processes the information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 05:17 PM
Security Audit — agent-trust-hub — purchase-testing