mpp-tempo-method
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to fetch and process content from external URLs and web search results.
- Ingestion points: Documentation from
docs.stripe.com,mpp.dev, and search results viaWebFetchandWebSearchas specified inSKILL.md. - Capability inventory: The agent is permitted to use
Write,Edit, andBashtools to configure the payment rails based on fetched data. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched external content as potentially untrusted data.
- Sanitization: The skill does not define validation or filtering steps for the information gathered from external sources.
- [EXTERNAL_DOWNLOADS]: The skill fetches technical specifications from
https://mpp.dev/overview. This source is used for documentation purposes and does not involve the execution of remote scripts or binary downloads. - [SAFE]: The provided code snippets demonstrate secure practices for handling sensitive data by utilizing environment variables (
process.env.MPP_SECRET_KEY) instead of hardcoding API keys or recipient addresses.
Audit Metadata