alipay-pay-for-service

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the official @alipay/agent-payment package from the npm registry. It incorporates a mandatory integrity check using a SHA-512 hash and version locking to ensure the security and authenticity of the downloaded code.- [COMMAND_EXECUTION]: The skill utilizes the alipay-bot CLI for payment operations. It provides explicit instructions for the agent to sanitize all inputs by wrapping them in single quotes and performing domain whitelist verification (restricted to alipay.com subdomains) on payment links before execution.- [DATA_EXFILTRATION]: While the skill interacts with external Alipay services, it is limited to official vendor infrastructure. It includes specific safety guidelines to filter sensitive user information, such as ID numbers and bank card details, from any output presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 05:09 AM
Security Audit — agent-trust-hub — alipay-pay-for-service