alipay-payment-integration
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill explicitly instructs the agent to fetch documentation from external URLs (e.g.,
https://ideservice.alipay.com/cms/site/0izcu3) and use that content to provide answers and code examples. This creates an attack surface where content on the remote server could influence the agent's behavior. - Ingestion points: Documentation URLs listed in
SKILL.mdto be fetched viacurlor browser tools. - Boundary markers: None. The agent is not instructed to treat the fetched content as untrusted or to sanitize it for potential instructions.
- Capability inventory: The skill expects the agent to execute shell commands (
curl) and process the resulting data. - Sanitization: None provided in the instructions.
- [COMMAND_EXECUTION]: The skill provides template
curlcommands for the agent to execute in order to retrieve documentation. While the target domainideservice.alipay.comis a well-known service belonging to Alipay, the instructions encourage the agent to run these network commands and recursively parse the output.
Audit Metadata