pricing-plans
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the
@kelviq/mcp-serverNode.js package for setup. This is a legitimate resource originating from the skill author ('kelviq'). - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface due to its data processing capabilities.
- Ingestion points: External data enters the agent context via the
kelviq:docs_read,kelviq:plan_retrieve, andkelviq:offering_get_producttools. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the documentation fetching flow.
- Capability inventory: The skill can create, update, and publish pricing models, features, and entitlements across a product catalog.
- Sanitization: There is no mention of sanitization or schema validation for the data retrieved from the documentation or API endpoints.
Audit Metadata