subscription-lifecycle

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to ingest configuration from an external project file (CLAUDE.md) and subscription data from the Stripe API. This creates an indirect prompt injection surface where maliciously crafted data in these sources could potentially influence agent behavior.\n
  • Ingestion points: Project configuration in CLAUDE.md and subscription objects retrieved from the Stripe API.\n
  • Boundary markers: The skill does not define specific delimiters or instructions to treat ingested data as untrusted, which could lead to instructions embedded in data being executed.\n
  • Capability inventory: The skill enables state transitions and account management via the stripe CLI and API, providing a path for data-driven actions.\n
  • Sanitization: No explicit sanitization or validation logic is described for the data retrieved from the configuration file or the external service.\n- [COMMAND_EXECUTION]: The skill provides instructions and examples for using the stripe CLI (e.g., stripe subscriptions retrieve, stripe subscriptions update) to manage customer billing states. These operations are intended for managing data on the Stripe platform, a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 06:25 AM