mpp-session-flow
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional content and architectural patterns for implementing payment flows. No malicious code, obfuscation, or unauthorized access patterns were detected.
- [EXTERNAL_DOWNLOADS]: Fetches documentation and API references from well-known sources including
npmjs.comandpaymentauth.orgto guide the implementation process. - [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to ingest and act upon content from external documentation sites.
- Ingestion points: External documentation URLs (NPM, paymentauth.org) and web search results.
- Boundary markers: None identified in the instructions for handling external data.
- Capability inventory: The skill configuration allows access to sensitive tools including
Bash,Write, andEdit. - Sanitization: No explicit sanitization or validation of the fetched documentation is prescribed.
Audit Metadata