lemonsqueezy-admin

Warn

Audited by Gen Agent Trust Hub on Feb 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION] (MEDIUM): The skill references an external command ls-admin for managing store data. No implementation code or package manifest is included, making the behavior of the executable unverifiable.\n- [PROMPT_INJECTION] (MEDIUM): High potential for Indirect Prompt Injection. Ingestion points: API responses from ls-admin orders and ls-admin subscriptions (File: SKILL.md). Boundary markers: None provided to delimit external data. Capability inventory: Shell command execution (File: SKILL.md). Sanitization: None. Attacker-controlled data in store records could influence subsequent agent actions.\n- [NO_CODE] (LOW): The provided files consist of markdown documentation and metadata only, with no executable logic to verify.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 14, 2026, 02:12 PM