magicpay
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with untrusted external data sources, including agent email threads (references/email.md) and merchant checkout pages (references/host-browser-payments.md). However, it implements a robust multi-stage 'footprint' and 'materialization' process in its Memory system to separate data discovery from use. Explicit instructions mandate that email and web content be treated as untrusted and never as authority for executing payments or account changes.
- [DATA_EXPOSURE]: The skill manages highly sensitive values such as passwords, API keys, and payment credentials. It includes strict guardrails (references/guardrails.md) that prohibit materializing these values in chat, replies, helper files, or exported logs. Secure materialization is handled via dedicated tool paths rather than plain text interpolation.
- [EXTERNAL_DOWNLOADS]: The skill fetches real-time exchange rates from Cloudflare-hosted api.frankfurter.dev (a well-known open-source API) to calculate USD pricing for non-USD merchant checkouts (references/host-browser-payments.md). This is a standard and transparent utility function.
- [COMMAND_EXECUTION]: The skill includes instructions for 'development session review' (references/development-session-review.md) which allow the agent to inspect logs or database projections using Supabase integrations. These operations are scoped to development environments and explicitly forbid requesting user tokens or printing secret-bearing payloads.
Audit Metadata