purchase-rebate-check-free

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file provides a pre-formatted prompt for the user to send to the AI agent. This prompt contains explicit authorization statements such as 'I have authorized the installation of dependencies and initiated the purchase,' which are used to influence the agent's decision-making process and potentially bypass interactive confirmation steps for high-privileged shell actions.
  • [EXTERNAL_DOWNLOADS]: The documentation describes the runtime installation of the @alipay/agent-payment package from the public npm registry using the command 'npx -y @alipay/agent-payment@latest install'. While targeting a well-known service provider to support the author's payment flow, the inclusion of runtime execution commands for external modules is a security-sensitive pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:28 AM
Security Audit — agent-trust-hub — purchase-rebate-check-free