payment-assistant

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external QR codes and Binance API response fields (such as payee names and remarks). This creates a surface for indirect prompt injection where malicious content could attempt to influence the agent's behavior.
  • Ingestion points: The --raw_qr parameter in payment_skill.py and various response fields parsed in send_extension/c2c.py and send_extension/pix.py.
  • Boundary markers: The skill instructions (SKILL.md) require the agent to wrap untrusted user-controlled fields with explicit markers (e.g., 「{payee_name}」) to separate them from system messages.
  • Capability inventory: The skill can execute shell commands via subprocess, perform network requests to Binance APIs, and write to the local file system.
  • Sanitization: The skill contains explicit rules forbidding the interpretation of API response fields as instructions and requires human confirmation before finalizing any payment action.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in send.py to execute system commands for capturing the clipboard image across different operating systems.
  • Evidence: It invokes osascript on macOS, powershell on Windows, and xclip on Linux. While these commands are used for a documented functional purpose (QR decoding), they represent active system interaction.
  • [DATA_EXFILTRATION]: The skill accesses the system clipboard to extract image data for QR code processing. This is a sensitive data exposure vector, although the skill mitigates risk by requiring the agent to wait for explicit user confirmation before accessing the clipboard.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:07 PM
Security Audit — agent-trust-hub — payment-assistant