payment-integration
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and provides instructions for installing SDKs and client-side libraries from established payment providers such as Stripe, Polar, Paddle, and Creem.io via official package registries and CDNs.
- [COMMAND_EXECUTION]: Includes a utility script
checkout-helper.jsand various cURL examples to assist developers in generating payment sessions and verifying webhooks. These tools are scoped to the primary payment integration use case. - [INDIRECT_PROMPT_INJECTION]: The skill processes external transaction data from webhooks. It explicitly provides security patterns for this, including HMAC SHA256 signature verification and HTML escaping for user-supplied metadata, mitigating injection risks.
- [SAFE]: A manual audit was conducted following an automated reputation alert on
SKILL.md. The file was found to contain only legitimate documentation, feature lists, and links to vendor resources, with no evidence of malicious code, obfuscation, or safety bypasses.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata