lemonsqueezy-admin
Warn
Audited by Gen Agent Trust Hub on Feb 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
- [COMMAND_EXECUTION] (MEDIUM): The skill references an external command
ls-adminfor managing store data. No implementation code or package manifest is included, making the behavior of the executable unverifiable.\n- [PROMPT_INJECTION] (MEDIUM): High potential for Indirect Prompt Injection. Ingestion points: API responses fromls-admin ordersandls-admin subscriptions(File: SKILL.md). Boundary markers: None provided to delimit external data. Capability inventory: Shell command execution (File: SKILL.md). Sanitization: None. Attacker-controlled data in store records could influence subsequent agent actions.\n- [NO_CODE] (LOW): The provided files consist of markdown documentation and metadata only, with no executable logic to verify.
Audit Metadata