stripe-integration
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides implementation templates for processing external data via webhook endpoints and API routes. The instructions mitigate injection and spoofing risks by enforcing the use of
stripe.webhooks.constructEventfor cryptographic signature verification and recommending database-backed idempotency checks to ensure data integrity. - [EXTERNAL_DOWNLOADS]: The documentation references official Stripe libraries (
@stripe/stripe-js,@stripe/react-stripe-js) and server-side SDKs (stripe,express). These are well-known, trusted dependencies essential for the skill's primary purpose of payment integration.
Audit Metadata