mpp-proxy

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation, API details, and official samples from NPM, GitHub, and Cloudflare. These are recognized and established sources for development information.
  • [INDIRECT_PROMPT_INJECTION]: The payment proxy implementation creates a data flow where untrusted inputs from clients are processed and relayed to other systems.
  • Ingestion points: Client request headers and body content are accessed via c.req.headers and c.req.text() in the SKILL.md code snippets.
  • Boundary markers: The provided templates lack explicit delimiters or instructions to ignore potential commands within the client-supplied data.
  • Capability inventory: The fetch function is employed in SKILL.md to relay client data to upstream API endpoints.
  • Sanitization: The example code does not include validation, escaping, or filtering of the proxied client information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM