payout-balance-report

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes data retrieved from the external Stripe API. 1. Ingestion points: Stripe API outputs from GetBalance, GetPayouts, and GetBalanceTransactions (SKILL.md). 2. Boundary markers: Absent; there are no instructions to use delimiters when processing API data. 3. Capability inventory: Uses Stripe MCP tools for searching and reading transaction data. 4. Sanitization: Absent; no specific instructions for filtering or sanitizing API responses are provided. This finding is considered low risk due to the structured reporting context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:33 PM
Security Audit — agent-trust-hub — payout-balance-report