card-funding-risk
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions to interact with the official Stripe API via the Stripe Model Context Protocol (MCP) using well-known tools like
stripe_api_searchandstripe_api_details.- [SAFE]: Includes explicit security guidelines for the agent, such as never exposing secret keys in the output and using official documentation for setup.- [PROMPT_INJECTION]: The skill ingests data from external Stripe subscription records. While this represents a surface for indirect prompt injection (Category 8), the risk is minimal as the ingested data is used for reporting purposes rather than being interpolated into executable commands or logic.- [DATA_EXPOSURE]: Accesses subscription and payment method details to perform its analysis. This behavior is transparently documented and aligns with the stated purpose of identifying high-risk funding sources for financial auditing.
Audit Metadata