mpp-proxy
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation, API details, and official samples from NPM, GitHub, and Cloudflare. These are recognized and established sources for development information.
- [INDIRECT_PROMPT_INJECTION]: The payment proxy implementation creates a data flow where untrusted inputs from clients are processed and relayed to other systems.
- Ingestion points: Client request headers and body content are accessed via
c.req.headersandc.req.text()in theSKILL.mdcode snippets. - Boundary markers: The provided templates lack explicit delimiters or instructions to ignore potential commands within the client-supplied data.
- Capability inventory: The
fetchfunction is employed inSKILL.mdto relay client data to upstream API endpoints. - Sanitization: The example code does not include validation, escaping, or filtering of the proxied client information.
Audit Metadata