payment-integration

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and provides instructions for installing SDKs and client-side libraries from established payment providers such as Stripe, Polar, Paddle, and Creem.io via official package registries and CDNs.
  • [COMMAND_EXECUTION]: Includes a utility script checkout-helper.js and various cURL examples to assist developers in generating payment sessions and verifying webhooks. These tools are scoped to the primary payment integration use case.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external transaction data from webhooks. It explicitly provides security patterns for this, including HMAC SHA256 signature verification and HTML escaping for user-supplied metadata, mitigating injection risks.
  • [SAFE]: A manual audit was conducted following an automated reputation alert on SKILL.md. The file was found to contain only legitimate documentation, feature lists, and links to vendor resources, with no evidence of malicious code, obfuscation, or safety bypasses.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 05:15 AM
Security Audit — agent-trust-hub — payment-integration