e-commerce
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard architectural patterns and TypeScript templates for e-commerce applications. No evidence of obfuscation, malicious commands, data exfiltration, or persistence mechanisms was found.
- [CREDENTIALS_UNSAFE]: The implementation follows security best practices by referencing environment variables (e.g.,
process.env.STRIPE_SECRET_KEY) for sensitive API credentials instead of hardcoding them within the skill. - [INDIRECT_PROMPT_INJECTION]: The skill manages untrusted data from product search inputs and Stripe payment webhooks. It mitigates potential risks through the use of industry-standard practices, including Stripe's built-in webhook signature verification (
stripe.webhooks.constructEvent) and parameterized database queries via Prisma.
Audit Metadata