upsell-expansion

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses official Stripe documentation and standard MCP tool patterns to interact with the Stripe API. No suspicious command execution, exfiltration, or persistence mechanisms were found.
  • [PROMPT_INJECTION]: This skill handles external data from Stripe (metadata), which is a vector for indirect prompt injection. The risk is considered safe due to the implementation of read-only defaults and user confirmation requirements. 1. Ingestion points: subscription metadata retrieved via CallMcpTool in SKILL.md. 2. Boundary markers: Not present. 3. Capability inventory: Data analysis and potential subscription updates via CallMcpTool. 4. Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:33 PM
Security Audit — agent-trust-hub — upsell-expansion