late-fee-check-free

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file includes a section titled "需要完整档时(可选)" (When needing the full version) that provides a pre-written text block explicitly intended for the AI agent. This block contains commands such as "请通过 SkillPay 购买并安装..." (Please buy and install via SkillPay...) and "我已授权安装依赖和发起购买" (I have authorized installing dependencies and initiating purchase), which are designed to override the agent's normal decision-making flow and direct it toward external actions.
  • [REMOTE_CODE_EXECUTION]: The documentation within SKILL.md directs the agent to execute npx -y @alipay/agent-payment@latest install. This command uses the Node Package Runner to download and execute code from the NPM registry. The package is associated with a well-known service.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to external domains for installation guides and purchase workflows, specifically skillpay.alipay.com and chenqg618.github.io. These references target a well-known service and the skill author's infrastructure.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 11:28 AM
Security Audit — agent-trust-hub — late-fee-check-free