e-commerce

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides standard architectural patterns and TypeScript templates for e-commerce applications. No evidence of obfuscation, malicious commands, data exfiltration, or persistence mechanisms was found.
  • [CREDENTIALS_UNSAFE]: The implementation follows security best practices by referencing environment variables (e.g., process.env.STRIPE_SECRET_KEY) for sensitive API credentials instead of hardcoding them within the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages untrusted data from product search inputs and Stripe payment webhooks. It mitigates potential risks through the use of industry-standard practices, including Stripe's built-in webhook signature verification (stripe.webhooks.constructEvent) and parameterized database queries via Prisma.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:04 AM
Security Audit — agent-trust-hub — e-commerce