tw-payment-integration

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical integration guide for Taiwan payment service providers (PSPs) like ECPay and NewebPay. All code snippets provided follow security best practices, emphasizing the importance of signature verification and using hosted payment pages to minimize PCI scope.
  • [CREDENTIALS_UNSAFE]: The MerchantID and Hash keys listed in references/ecpay-api.md are documented as official public sandbox credentials provided by ECPay for testing purposes. These are not sensitive production secrets.
  • [COMMAND_EXECUTION]: The shell commands included in references/pci-checklist.md (e.g., grep for SSH configuration, openssl for TLS testing) are provided as educational examples for security auditing and do not perform malicious actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:06 PM
Security Audit — agent-trust-hub — tw-payment-integration