extension-stripe

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes shopping item data which is subsequently passed to the Stripe API via network calls. This creates a surface where malicious content in product names or descriptions could influence the payment flow.
  • Ingestion points: The items array within the createCheckoutSession function in src/backend/main.mo.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat item names or descriptions as untrusted data.
  • Capability inventory: The backend performs HTTP outcalls to the Stripe API using the mo:caffeineai-stripe/stripe module.
  • Sanitization: There is no evidence of input validation, escaping, or filtering of the ShoppingItem fields before they are used in the session creation request.
  • [CREDENTIALS_UNSAFE]: The skill is designed to handle and store a Stripe secretKey in the application state.
  • Evidence: The StripeConfiguration type and the setStripeConfiguration function in src/backend/main.mo are explicitly used to manage sensitive API credentials.
  • Mitigation: The implementation includes a permission check (AccessControl.hasPermission) ensuring that only users with administrative privileges can update the Stripe configuration, which reduces the risk of unauthorized credential manipulation.
  • [COMMAND_EXECUTION]: The skill defines and uses shared functions in Motoko to execute payment logic and state transitions.
  • Evidence: Functions like createCheckoutSession, addProduct, and updateProduct in src/backend/main.mo allow for persistent state changes and external network interactions triggered by agent or user actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:14 PM
Security Audit — agent-trust-hub — extension-stripe