saas-platforms

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing external data from Stripe webhooks.
  • Ingestion points: handleSubscriptionWebhook in SKILL.md and the Stripe webhook endpoint in templates/README.md process external payloads.
  • Boundary markers: Not included in these basic templates.
  • Capability inventory: The skill utilizes the Prisma client for database operations and the Stripe SDK for subscription management.
  • Sanitization: Examples demonstrate casting to expected Stripe types; developers should implement cryptographic signature verification (as shown in the README.md webhook handler) for security.
  • [COMMAND_EXECUTION]: The skill references standard CLI tools for database management.
  • Evidence: templates/README.md includes npx prisma init, npx prisma generate, and npx prisma migrate dev for setting up the application environment.
  • [DYNAMIC_EXECUTION]: Examples for multi-tenant database isolation involve dynamic SQL generation.
  • Evidence: SKILL.md contains snippets using $executeRaw for creating schemas and databases dynamically. In production, these identifiers must be strictly validated or sanitized to prevent SQL injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:14 AM
Security Audit — agent-trust-hub — saas-platforms