connect-required-verification-information
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs HTTP GET requests to official Stripe documentation endpoints (e.g.,
docs.stripe.com/_endpoint/...) to fetch configuration maps, capabilities, and country lists. These are read-only operations targeting a well-known, trusted service provider to provide accurate documentation to the user. - [COMMAND_EXECUTION]: The skill provides
curlexamples in its documentation to illustrate how to interact with the Stripe documentation API. These are educational placeholders intended for the user to understand the underlying data flow and do not represent autonomous malicious command execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Stripe's API (such as country lists and capability maps). While it lacks explicit sanitization instructions for this data, the threat is categorized as low/safe because the source is a trusted provider, and the skill implements strict boundary logic and multiple-choice constraints that limit the influence of external content on the agent's behavior.
Audit Metadata