moyasar

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive integration logic for the Moyasar payment gateway, a legitimate financial service in Saudi Arabia.
  • [SAFE]: All network requests are directed to the service's official API domains: api.moyasar.com and apimig.moyasar.com.
  • [SAFE]: The skill emphasizes critical security protocols, including the strict separation of publishable (pk_) and secret (sk_) keys and the mandatory server-side verification of payment statuses to prevent spoofing or tampering.
  • [SAFE]: The included code assets (assets/moyasar-client.ts and scripts/verify_payment.py) are functional tools that implement standard security practices like HTTP Basic Auth and constant-time comparison for webhook validation.
  • [SAFE]: No evidence of prompt injection, malicious data exfiltration, or obfuscation techniques was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 12:17 PM
Security Audit — agent-trust-hub — moyasar