inventory-provision-check-free

Fail

Audited by Snyk on Sep 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (critical risk: 1.00). The skill promotes purchasing a paid full version via external payment instructions and links, which violates the prohibition against promoting donations, wallets, liquidity deposits, cryptocurrency transfers, or financial transactions inside a non-financial skill.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill instructs the agent and user to download, install, and execute a package from an external platform via npx -y @alipay/agent-payment@latest install, constituting an unverifiable runtime external dependency under weak/unknown provenance.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 16, 2026, 11:27 AM
Issues
2
Security Audit — snyk — inventory-provision-check-free