stripe-integration-expert

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The integration_auditor.py and webhook_validator.py scripts ingest and process data from user-provided project directories, which constitutes an indirect prompt injection surface.
  • Ingestion points: The scripts read the content of all source files within a specified project_dir provided as a command-line argument to the auditor and validator tools.
  • Boundary markers: Absent. The scripts read raw file content into memory for pattern matching without specific delimiters or instructions that would prevent an LLM from interpreting instructions embedded within the scanned code.
  • Capability inventory: The skill includes Python scripts that perform directory traversal and file reading. It also provides reference code for network-based webhook handlers and checkout sessions. The scripts do not execute the code they scan or perform network operations based on the scanned content.
  • Sanitization: The scripts use standard file reading practices with errors="replace" to safely handle non-UTF-8 characters during the scanning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:53 PM
Security Audit — agent-trust-hub — stripe-integration-expert