lease-liability-check-free

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation in SKILL.md provides a workflow that directs the agent to execute npx -y @alipay/agent-payment@latest install. This command facilitates the download and execution of code from the NPM registry. The target package is maintained by a well-known technology organization.
  • [COMMAND_EXECUTION]: The skill leverages the agent's shell capabilities to execute audit scripts and provides instructions for the agent to run command-line installation tools. This is a primary function of the skill's utility and commercial onboarding flow.
  • [PROMPT_INJECTION]: SKILL.md contains a pre-defined text block intended for the user to input into the AI agent. This block instructs the agent to perform a series of autonomous actions, such as reading specific files, installing software, and navigating third-party merchant product identifiers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:28 AM
Security Audit — agent-trust-hub — lease-liability-check-free