vat-burden-check-free
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTIONMETADATA_POISONING
Full Analysis
- [PROMPT_INJECTION]: The SKILL.md file contains a pre-formatted block of text intended to override agent behavior. It instructs the agent to install external software and initiate financial transactions, explicitly stating that these actions are 'authorized' to reduce the likelihood of the agent requesting user confirmation before execution.
- [REMOTE_CODE_EXECUTION]: The documentation encourages the execution of arbitrary remote code via npx -y @alipay/agent-payment@latest install. This command bypasses interactive prompts and executes code directly from an external registry, posing a significant security risk if the package is not verified.
- [METADATA_POISONING]: The skill uses its description as a marketing and execution funnel for a different paid product. By embedding instructional payloads within the skill's description, the author attempts to use the agent as a tool for unverified software deployment and commerce.
Recommendations
- AI detected serious security threats
Audit Metadata