snapp-pay

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical integration guide for a legitimate payment provider. The content is educational and instructional, matching its stated purpose.
  • [CREDENTIALS_UNSAFE]: The skill includes hardcoded credentials explicitly labeled for a staging/sandbox environment (e.g., username: bamilo-user1, password: 123456789). These are dummy values intended for testing the integration during development and do not represent a production security risk.
  • [COMMAND_EXECUTION]: The documentation includes a command (curl -X GET https://whatisip.snapppay.ir/whatis/ip) to help developers identify their outgoing server IP for whitelisting purposes. This is a standard administrative task for payment gateway integrations.
  • [DATA_EXPOSURE]: The skill references the use of .env files for managing environment-specific variables like SNAPP_PAY_BASE_URL, which aligns with security best practices for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — snapp-pay