mpp-session-flow

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional content and architectural patterns for implementing payment flows. No malicious code, obfuscation, or unauthorized access patterns were detected.
  • [EXTERNAL_DOWNLOADS]: Fetches documentation and API references from well-known sources including npmjs.com and paymentauth.org to guide the implementation process.
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to ingest and act upon content from external documentation sites.
  • Ingestion points: External documentation URLs (NPM, paymentauth.org) and web search results.
  • Boundary markers: None identified in the instructions for handling external data.
  • Capability inventory: The skill configuration allows access to sensitive tools including Bash, Write, and Edit.
  • Sanitization: No explicit sanitization or validation of the fetched documentation is prescribed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 06:10 AM