property-fee-check-free
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHPROMPT_INJECTIONMETADATA_POISONINGREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill's documentation contains a pre-formatted block of instructions intended to be processed by the AI agent. These instructions direct the agent to purchase and install additional software and execute shell commands while explicitly commanding the agent to bypass standard safety confirmation steps ('我已授权安装依赖和发起购买... 不要替我确认'). This represents a direct attempt to hijack the agent's operational constraints and safety filters.
- [METADATA_POISONING]: The skill is marketed as a 'Free' tool ('property-fee-check-free'), yet its documentation primarily serves as a delivery vector for upselling a paid version and providing the associated injection payloads. This deceptive labeling can lead users to grant permissions or execute instructions that facilitate the hijacked behavior.
- [REMOTE_CODE_EXECUTION]: The skill documentation provides instructions that lead the agent to execute 'npx -y @alipay/agent-payment@latest install', which downloads and runs code from a remote registry. When combined with the instruction to suppress user confirmation and oversight, this presents a high risk of unauthorized and unvetted code execution on the user's system.
Recommendations
- AI detected serious security threats
Audit Metadata