stripe-apps

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform local development tasks including project initialization using stripe generate app, dependency installation via pnpm install, and executing build or test scripts. These are standard operations for a software development agent and are restricted to the local development environment.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data to ensure generated code remains current with Stripe's API standards. This creates a theoretical surface where external content could influence the agent's logic.
  • Ingestion points: The skill utilizes WebFetch to read live documentation from docs.stripe.com as defined in references/canonical-docs.md.
  • Boundary markers: The instructions do not specify explicit delimiters or isolation markers for the content retrieved via WebFetch.
  • Capability inventory: The agent possesses Bash (shell execution), Write (file system modification), and WebFetch (network read) capabilities.
  • Sanitization: The skill relies on the integrity of the well-known and trusted Stripe documentation domain rather than programmatic sanitization of the fetched data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:41 PM