integrate-easypaisa
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive security instructions for implementing payment integrations. Key safety measures include:
- [CREDENTIALS_UNSAFE]: Explicitly forbids hardcoding merchant credentials or signing keys in browser code, mobile apps, logs, or repositories, recommending managed secret storage.
- [DATA_EXFILTRATION]: No network operations or unauthorized data access patterns were detected. The skill focuses on standard payment gateway communication.
- [INDIRECT_PROMPT_INJECTION]: The skill addresses the inherent risk of processing external payment callbacks by mandating server-side verification, message integrity checks (HMAC/signatures), and source authentication. It correctly warns against trusting client-side status indicators.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, package installations, or dynamic code execution were found.
- [EXTERNAL_DOWNLOADS]: References to external documentation and portals target official Easypaisa domains (easypaisa.com.pk) and well-known community platforms (Reddit), which are considered safe sources for technical research.
Audit Metadata