purchase-testing
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the official
adaptyCLI package globally using the Node Package Manager (NPM). This tool is essential for the skill's diagnostic capabilities and is sourced from a well-known public registry.\n - Evidence:
npm i -g adapty@latestinSKILL.md.\n- [COMMAND_EXECUTION]: The skill performs multiple shell command executions to interface with the Adapty API via its CLI tool. These commands retrieve metadata about app placements, products, and access levels to diagnose purchase failures.\n - Evidence: Commands such as
$ADAPTY auth whoami,$ADAPTY placements list, and$ADAPTY flows config getare found inSKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically the output of CLI commands and application code, to analyze and report findings to the user. This represents an attack surface where malicious instructions could be embedded in the data being processed.\n - Ingestion points: Output of
adaptyCLI commands and project source code (viagrep) inSKILL.md.\n - Boundary markers: The instructions direct the agent to report findings in a specific "short block," providing some logical separation, but no explicit delimiters or "ignore instructions" markers are defined for the external data.\n
- Capability inventory: File reading (
grep), shell command execution (adaptyCLI), and network operations (via the CLI tool) inSKILL.md.\n - Sanitization: No explicit sanitization, validation, or escaping of the CLI output or code contents is performed before the agent processes the information.
Audit Metadata