snapp-pay
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical integration guide for a legitimate payment provider. The content is educational and instructional, matching its stated purpose.
- [CREDENTIALS_UNSAFE]: The skill includes hardcoded credentials explicitly labeled for a staging/sandbox environment (e.g., username:
bamilo-user1, password:123456789). These are dummy values intended for testing the integration during development and do not represent a production security risk. - [COMMAND_EXECUTION]: The documentation includes a command (
curl -X GET https://whatisip.snapppay.ir/whatis/ip) to help developers identify their outgoing server IP for whitelisting purposes. This is a standard administrative task for payment gateway integrations. - [DATA_EXPOSURE]: The skill references the use of
.envfiles for managing environment-specific variables likeSNAPP_PAY_BASE_URL, which aligns with security best practices for secret management.
Audit Metadata