saas-platforms
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing external data from Stripe webhooks.
- Ingestion points:
handleSubscriptionWebhookinSKILL.mdand the Stripe webhook endpoint intemplates/README.mdprocess external payloads. - Boundary markers: Not included in these basic templates.
- Capability inventory: The skill utilizes the Prisma client for database operations and the Stripe SDK for subscription management.
- Sanitization: Examples demonstrate casting to expected Stripe types; developers should implement cryptographic signature verification (as shown in the
README.mdwebhook handler) for security. - [COMMAND_EXECUTION]: The skill references standard CLI tools for database management.
- Evidence:
templates/README.mdincludesnpx prisma init,npx prisma generate, andnpx prisma migrate devfor setting up the application environment. - [DYNAMIC_EXECUTION]: Examples for multi-tenant database isolation involve dynamic SQL generation.
- Evidence:
SKILL.mdcontains snippets using$executeRawfor creating schemas and databases dynamically. In production, these identifiers must be strictly validated or sanitized to prevent SQL injection.
Audit Metadata