stripe-webhooks

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious behavior or high-risk patterns were identified during the security audit. The skill follows developer best practices for handling sensitive payment data.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides code that ingests external data via webhook endpoints. Ingestion points are located in examples/express/src/index.js, examples/fastapi/main.py, and examples/nextjs/app/webhooks/stripe/route.ts. The skill correctly implements Stripe signature verification using the official SDK as a boundary marker and sanitization step. The inventory of capabilities shows no high-risk operations are performed with the ingested data.
  • [CREDENTIALS_UNSAFE]: The skill correctly handles sensitive credentials by instructing users to use environment variables (STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET). Example files contain safe placeholders and follow industry standards for secret management.
  • [EXTERNAL_DOWNLOADS]: The documentation references official developer tools from Stripe and Hookdeck for local development and testing, which are well-known sources for this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — stripe-webhooks