labor-cost-allocation-check-free

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file contains a pre-written text block intended for the user to provide to their AI assistant. This block contains multi-step instructions that direct the assistant to install a tool and purchase a 'Full Version' using hardcoded IDs. Significant sections of this text, such as 'I have authorized the installation of dependencies... do not confirm on my behalf', are designed to bypass or override the agent's standard confirmation and safety protocols regarding financial transactions and software installation.\n- [EXTERNAL_DOWNLOADS]: The automation instructions included in the SKILL.md file encourage the agent to execute npx -y @alipay/agent-payment@latest install. This command downloads and runs code from the public npm registry. While the @alipay scope is associated with a well-known financial service provider, the use of npx with the auto-accept flag within a documentation-driven workflow represents an external code execution pattern initiated by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:28 AM
Security Audit — agent-trust-hub — labor-cost-allocation-check-free