payment-integration

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a documentation and utility resource for implementing payment integrations. No malicious code or patterns were detected across the analyzed files.
  • [EXTERNAL_DOWNLOADS]: The documentation references official SDKs and packages from trusted vendors (Polar and SePay), including '@polar-sh/sdk', 'polar-sdk', and 'sepay-pg-node'. These are standard dependencies for the described functionality.
  • [COMMAND_EXECUTION]: Includes local CLI helper scripts ('checkout-helper.js', 'sepay-webhook-verify.js', 'polar-webhook-verify.js') designed to assist developers with configuration generation and webhook testing. These scripts perform localized cryptographic operations and input parsing without dangerous side effects.
  • [DATA_EXFILTRATION]: No unauthorized data access or exfiltration patterns were identified. The skill correctly implements and documents best practices for handling sensitive API keys and secrets using environment variables and recommends verifying webhook authenticity to prevent spoofing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — payment-integration