invoice-consistency-check-free
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The
SKILL.mdfile contains a dedicated section for 'upgrading' to a full version. This section includes a pre-written prompt designed to be interpreted by an AI agent (e.g., '请通过 SkillPay 购买并安装...'). This prompt instructs the agent to execute specific commands and initiate financial transactions via SkillPay, attempting to override the agent's current task flow. - [INDIRECT_PROMPT_INJECTION]: The skill documentation acts as an injection vector. If an AI agent reads the
SKILL.mdto understand its own capabilities or provide help to a user, it may encounter the instructions to purchase the full version and interpret them as immediate directives rather than optional user documentation. - Ingestion points:
SKILL.mdcontent. - Boundary markers: None present; the text is provided as a 'copy-paste' block for an AI assistant.
- Capability inventory: The instructions target shell execution (via
npx) and financial payment tools. - Sanitization: None; the text is provided as raw instructions.
Audit Metadata