bid-deposit-refund-check-free

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data in the form of bid deposit tables and incorporates parts of this data into its output findings. • Ingestion points: The 'text' property of the input payload processed in scripts/engine/bid-deposit-refund-check.js. • Boundary markers: None. The skill does not provide instructions to the agent to ignore embedded commands within the table data. • Capability inventory: The skill possesses Bash and Read capabilities as defined in SKILL.md. • Sanitization: The skill performs numeric normalization but does not sanitize string fields like '投标人' (bidder) before including them in the findings reports.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions for the user to execute an npx command to install a payment-related package from a well-known service.
  • [PROMPT_INJECTION]: The SKILL.md file contains a section of text designed to be copied and sent to the AI agent. This text provides specific instructions for the agent to follow regarding the installation of dependencies and the execution of a purchase, including constraints on confirmation behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:28 AM
Security Audit — agent-trust-hub — bid-deposit-refund-check-free