stripe-webhooks
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious behavior or high-risk patterns were identified during the security audit. The skill follows developer best practices for handling sensitive payment data.
- [INDIRECT_PROMPT_INJECTION]: The skill provides code that ingests external data via webhook endpoints. Ingestion points are located in
examples/express/src/index.js,examples/fastapi/main.py, andexamples/nextjs/app/webhooks/stripe/route.ts. The skill correctly implements Stripe signature verification using the official SDK as a boundary marker and sanitization step. The inventory of capabilities shows no high-risk operations are performed with the ingested data. - [CREDENTIALS_UNSAFE]: The skill correctly handles sensitive credentials by instructing users to use environment variables (
STRIPE_SECRET_KEY,STRIPE_WEBHOOK_SECRET). Example files contain safe placeholders and follow industry standards for secret management. - [EXTERNAL_DOWNLOADS]: The documentation references official developer tools from Stripe and Hookdeck for local development and testing, which are well-known sources for this context.
Audit Metadata