stripe-apps
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform local development tasks including project initialization usingstripe generate app, dependency installation viapnpm install, and executing build or test scripts. These are standard operations for a software development agent and are restricted to the local development environment.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data to ensure generated code remains current with Stripe's API standards. This creates a theoretical surface where external content could influence the agent's logic. - Ingestion points: The skill utilizes
WebFetchto read live documentation fromdocs.stripe.comas defined inreferences/canonical-docs.md. - Boundary markers: The instructions do not specify explicit delimiters or isolation markers for the content retrieved via
WebFetch. - Capability inventory: The agent possesses
Bash(shell execution),Write(file system modification), andWebFetch(network read) capabilities. - Sanitization: The skill relies on the integrity of the well-known and trusted Stripe documentation domain rather than programmatic sanitization of the fetched data.
Audit Metadata