card-funding-risk

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions to interact with the official Stripe API via the Stripe Model Context Protocol (MCP) using well-known tools like stripe_api_search and stripe_api_details.- [SAFE]: Includes explicit security guidelines for the agent, such as never exposing secret keys in the output and using official documentation for setup.- [PROMPT_INJECTION]: The skill ingests data from external Stripe subscription records. While this represents a surface for indirect prompt injection (Category 8), the risk is minimal as the ingested data is used for reporting purposes rather than being interpolated into executable commands or logic.- [DATA_EXPOSURE]: Accesses subscription and payment method details to perform its analysis. This behavior is transparently documented and aligns with the stated purpose of identifying high-risk funding sources for financial auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:32 PM
Security Audit — agent-trust-hub — card-funding-risk