skills/hktitan/swiggy-cli/swiggy-pay/Gen Agent Trust Hub

swiggy-pay

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the swiggy CLI tool to check payment status and confirm orders. The commands involve passing parameters like paasId, orderId, and geographic coordinates to the tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external responses (such as the place-order output and meta.message) and interpolates these into logic or reports them to the user, creating a potential vector for indirect instructions.
  • Ingestion points: The skill ingests data from the place-order response (paasId, orderId, addressId, lat, lng) and processes the output of the swiggy tool (e.g., meta.message).
  • Boundary markers: No explicit delimiters or boundary markers are defined to isolate untrusted data from the agent's instructions.
  • Capability inventory: The skill is capable of executing the swiggy command-line tool with various subcommands and flags.
  • Sanitization: There is no evidence of sanitization, escaping, or validation of external content before it is processed or reported to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:16 AM
Security Audit — agent-trust-hub — swiggy-pay