tw-ecom-payment-newebpay
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, prompt injections, or obfuscated code were found in the skill.
- [SAFE]: The instructions promote secure handling of sensitive data by using environment variables for API keys and IVs instead of hardcoding them.
- [SAFE]: The skill emphasizes cryptographic verification of transaction signatures (TradeSha) and AES-256-CBC decryption of payment notifications to ensure data integrity.
- [SAFE]: The guidance correctly distinguishes between client-side redirects (ReturnURL) and server-side webhooks (NotifyURL), establishing the latter as the canonical source of truth for payment status.
Audit Metadata