stripe-integration
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The content consists of legitimate educational material for Stripe payment processing. The documentation provides standard integration patterns for checkout, subscriptions, and webhooks.
- [CREDENTIALS_UNSAFE]: No sensitive credentials are exposed. The code examples use standard prefixes and placeholders like 'sk_test_...' for API keys and 'whsec_...' for webhook secrets, which is the industry-standard safe practice for technical documentation.
- [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external data via webhooks, it explicitly demonstrates security best practices such as signature verification using stripe.Webhook.construct_event to ensure data integrity and authenticity.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill uses standard, well-known libraries (Stripe, Flask) for its intended purpose without suspicious dynamic execution or piped shell commands.
Audit Metadata