tax-incentive-eligibility-check-free

Fail

Audited by Snyk on Sep 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (critical risk: 1.00). The skill contains instructions and code that promote and facilitate the purchase and installation of a paid counterpart product via external payment flows.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill contains instructions and code suggesting the agent execute npx -y @alipay/agent-payment@latest install to fetch and install a remote payment and dependency package from an unofficial/arbitrary repository channel, presenting an operational dependency with weak provenance.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 16, 2026, 11:28 AM
Issues
2
Security Audit — snyk — tax-incentive-eligibility-check-free