mpp-tempo-method

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to fetch and process content from external URLs and web search results.
  • Ingestion points: Documentation from docs.stripe.com, mpp.dev, and search results via WebFetch and WebSearch as specified in SKILL.md.
  • Capability inventory: The agent is permitted to use Write, Edit, and Bash tools to configure the payment rails based on fetched data.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched external content as potentially untrusted data.
  • Sanitization: The skill does not define validation or filtering steps for the information gathered from external sources.
  • [EXTERNAL_DOWNLOADS]: The skill fetches technical specifications from https://mpp.dev/overview. This source is used for documentation purposes and does not involve the execution of remote scripts or binary downloads.
  • [SAFE]: The provided code snippets demonstrate secure practices for handling sensitive data by utilizing environment variables (process.env.MPP_SECRET_KEY) instead of hardcoding API keys or recipient addresses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM