billing-setup
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages billing configurations using vendor-authorized MCP tools (credyt:*). It adheres to security best practices by requiring the user to explicitly confirm a summary table of parameters before any data creation or modification occurs.- [SAFE]: An indirect prompt injection surface exists where user input is used for tool parameters. This is safely managed as follows: (1) Ingestion points: user answers during discovery questions; (2) Boundary markers: manual confirmation tables; (3) Capability inventory: specific billing-related MCP tools; (4) Sanitization: mandatory user review of data before tool execution.- [SAFE]: No indicators of credential harvesting, unauthorized network access, obfuscation, or remote code execution were found. The skill's functionality is transparent and aligned with its documented purpose.
Audit Metadata