swiggy-mcp-payments

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions or metadata.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation from mcp.swiggy.com, which is a well-known service domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface via check_payment_status.data in SKILL.md. Boundary markers are absent. Capabilities include calling the confirm_order tool. Sanitization is partially addressed by instructions to echo identifiers verbatim without reconstruction. The risk is assessed as safe given the controlled environment of the payment server responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:16 AM
Security Audit — agent-trust-hub — swiggy-mcp-payments