fixed-asset-count-check-free

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file includes a text block intended for the user to provide to their AI assistant. This block contains directives ("I have authorized installation and purchase", "do not confirm for me") aimed at pre-approving actions and potentially bypassing standard user confirmation steps within supported agent payment frameworks.- [REMOTE_CODE_EXECUTION]: Documentation within the skill suggests executing code from the public NPM registry via npx -y @alipay/agent-payment@latest install. While this targets a well-known service (Alipay), it involves the retrieval and execution of remote code.- [EXTERNAL_DOWNLOADS]: The skill documentation references external domains for supplementary guides and commercial versions, including skillpay.alipay.com and a vendor-managed site at chenqg618.github.io.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:28 AM
Security Audit — agent-trust-hub — fixed-asset-count-check-free