lesson-hour-check-free
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The core logic in
scripts/engine/lesson-hour-check.jsand the execution scriptscripts/run.mjsare implemented using standard Node.js libraries and perform deterministic data processing. No network operations, sensitive file access, or obfuscation were detected in the source code. - [REMOTE_CODE_EXECUTION]: The documentation in
SKILL.mdprovides instructions for the user to have the agent executenpx -y @alipay/agent-payment@latest install. This command downloads and runs code from the official NPM registry. The package belongs to the@alipayorganization, which is a well-known and reputable technology provider. - [PROMPT_INJECTION]: The
SKILL.mdfile contains a pre-written text block intended for the user to copy and send to the AI assistant. This block contains specific instructions to guide the agent through a purchase and installation process for a premium version of the tool, including explicit authorization for dependency installation.
Audit Metadata