skills/blindpaylabs/skills/blindpay/Gen Agent Trust Hub

blindpay

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No security issues detected. All analyzed files provide standard documentation and integration instructions for the BlindPay API.
  • [CREDENTIALS_UNSAFE]: The documentation uses clear placeholders like 'YOUR_API_KEY' and 'YOUR_SECRET_TOKEN'. It explicitly warns users to keep keys server-side and avoid exposing them in client-side code or version control.
  • [EXTERNAL_DOWNLOADS]: The skill references official resources on 'blindpay.com' and repositories under the 'blindpaylabs' GitHub organization. These are verified vendor resources.
  • [REMOTE_CODE_EXECUTION]: Installation instructions use standard package managers to fetch official vendor SDKs and tools, which is consistent with the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an integration surface for analyzing untrusted document files with AI. The risks associated with processing these documents are mitigated by the provider's stated safety filters and the lack of dangerous local execution capabilities in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 03:46 PM
Security Audit — agent-trust-hub — blindpay