pricing-update
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads pricing guidelines from cursor.com and a verification file from the author's GitHub Pages domain (robinebers.github.io). Both sources are legitimate and consistent with the skill's purpose.- [COMMAND_EXECUTION]: The skill uses local shell commands for validation and testing, such as python3 for JSON verification and swift test for regression checks. These commands use static code provided within the skill instructions.- [REMOTE_CODE_EXECUTION]: Analysis of the automated scan finding indicates a false positive. The command pipes JSON data from the author's domain into python3 -c for parsing a specific field, which does not involve executing the remote content as code.- [PROMPT_INJECTION]: The skill ingests data from external documentation, presenting a theoretical indirect prompt injection surface. Evidence chain: (1) Ingestion point: Step 1 fetches external markdown; (2) Boundary markers: Absent; (3) Capability inventory: Local file writes and script execution; (4) Sanitization: Absent. The risk is minimized by the reputable source of the documentation.
Audit Metadata