inventory-scrap-approval-check-free

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The inventory audit engine and its CLI wrapper are implemented using standard Node.js libraries and execute entirely within the local environment. No network requests or sensitive data exfiltration patterns were detected in the source code.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation guides users through an optional upgrade process that involves installing a utility from a well-known service provider's package registry (@alipay/agent-payment). This behavior is part of the established commercial workflow for the vendor.
  • [PROMPT_INJECTION]: The documentation contains a recommended prompt designed to facilitate the purchase of a 'buy-out' version of the skill. While this involves instructing the AI to perform specific actions like dependency installation, it serves a legitimate functional purpose within the platform's ecosystem.
  • [REMOTE_CODE_EXECUTION]: The provided installation instructions utilize 'npx' to run code from a remote repository. This is used specifically to install the payment handler for the platform and originates from a well-known organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:29 AM
Security Audit — agent-trust-hub — inventory-scrap-approval-check-free