lesson-hour-check-free

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The core logic in scripts/engine/lesson-hour-check.js and the execution script scripts/run.mjs are implemented using standard Node.js libraries and perform deterministic data processing. No network operations, sensitive file access, or obfuscation were detected in the source code.
  • [REMOTE_CODE_EXECUTION]: The documentation in SKILL.md provides instructions for the user to have the agent execute npx -y @alipay/agent-payment@latest install. This command downloads and runs code from the official NPM registry. The package belongs to the @alipay organization, which is a well-known and reputable technology provider.
  • [PROMPT_INJECTION]: The SKILL.md file contains a pre-written text block intended for the user to copy and send to the AI assistant. This block contains specific instructions to guide the agent through a purchase and installation process for a premium version of the tool, including explicit authorization for dependency installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:28 AM
Security Audit — agent-trust-hub — lesson-hour-check-free