stripe-integration

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill uses non-sensitive placeholders (e.g., 'sk_test_...') for API keys and secrets in its code examples, following safe documentation practices.
  • [DATA_EXFILTRATION]: Analysis found no evidence of unauthorized data exfiltration. The network activity is restricted to standard Stripe API interactions and user-defined application URLs.
  • [REMOTE_CODE_EXECUTION]: The skill does not attempt to download or execute external code. All logic is contained within the provided scripts using standard libraries.
  • [PROMPT_INJECTION]: No instructional overrides or jailbreak patterns were identified; the skill remains focused on its stated purpose of payment integration.
  • [COMMAND_EXECUTION]: There are no attempts to perform dangerous shell commands, privilege escalation, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 12:24 PM
Security Audit — agent-trust-hub — stripe-integration