skills/celeroncoder/skills/payload/Gen Agent Trust Hub

payload

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a comprehensive developer reference for Payload CMS, providing legitimate documentation and code patterns.
  • [SAFE]: The skill promotes security best practices, including explicit warnings about common pitfalls like the default overrideAccess behavior in the Local API and the importance of threading the request object through hooks to maintain transaction atomicity.
  • [EXTERNAL_DOWNLOADS]: References official Payload CMS packages and well-known, trusted service providers such as Stripe, AWS, Cloudflare, and Vercel for various integrations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and manage project source code and configuration.
  • Ingestion points: Processes project-specific configuration files (payload.config.ts), collection definitions, and hook logic.
  • Boundary markers: Utilizes clear Markdown structure and dedicated Security Pitfalls sections to delineate guidance.
  • Capability inventory: Standard development environment capabilities for file system management and execution of build/dev tools.
  • Sanitization: Encourages the use of overrideAccess: false to ensure user-space permissions are respected during operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — payload