setup-bcl
Pass
Audited by Gen Agent Trust Hub on May 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate instructions for the BCL payment gateway and references official documentation at
docs.bcl.my. - [SAFE]: Instructions explicitly mandate security best practices, such as keeping API and portal keys on the server-side and verifying payment states via server-to-server calls rather than browser redirects.
- [SAFE]: All external references point to vendor-controlled domains and storage buckets (e.g.,
bcl-media.s3.ap-southeast-1.amazonaws.com). - [SAFE]: No malicious patterns, prompt injections, or unauthorized data access commands were found.
Audit Metadata