stripe-subscriptions
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses network operations to fetch external markdown content from a third-party domain.
- Evidence: Multiple instances of
curl -H "Accept: text/markdown" https://fullstackrecipes.com/api/recipes/...found inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates a vulnerability surface for indirect prompt injection by design, as it fetches and processes content from external, untrusted sources.
- Ingestion points: External recipe content is fetched via
curland provided to the agent context withinSKILL.md. - Boundary markers: Absent; there are no clear delimiters or instructions to the agent to treat the fetched content as untrusted data.
- Capability inventory: The instructions guide the agent to perform sensitive configuration tasks, including setting up environment variables (
better-env), database connections (Neon + Drizzle), and Stripe webhook handling. - Sanitization: Absent; the skill does not implement any filtering or verification of the content retrieved from the external domain.
Audit Metadata