extension-stripe
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes shopping item data which is subsequently passed to the Stripe API via network calls. This creates a surface where malicious content in product names or descriptions could influence the payment flow.
- Ingestion points: The
itemsarray within thecreateCheckoutSessionfunction insrc/backend/main.mo. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat item names or descriptions as untrusted data.
- Capability inventory: The backend performs HTTP outcalls to the Stripe API using the
mo:caffeineai-stripe/stripemodule. - Sanitization: There is no evidence of input validation, escaping, or filtering of the
ShoppingItemfields before they are used in the session creation request. - [CREDENTIALS_UNSAFE]: The skill is designed to handle and store a Stripe
secretKeyin the application state. - Evidence: The
StripeConfigurationtype and thesetStripeConfigurationfunction insrc/backend/main.moare explicitly used to manage sensitive API credentials. - Mitigation: The implementation includes a permission check (
AccessControl.hasPermission) ensuring that only users with administrative privileges can update the Stripe configuration, which reduces the risk of unauthorized credential manipulation. - [COMMAND_EXECUTION]: The skill defines and uses shared functions in Motoko to execute payment logic and state transitions.
- Evidence: Functions like
createCheckoutSession,addProduct, andupdateProductinsrc/backend/main.moallow for persistent state changes and external network interactions triggered by agent or user actions.
Audit Metadata