payermax-integration-assistant

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform local command execution using openssl to generate and validate 2048-bit PKCS#8 RSA keypairs. This is a legitimate functional requirement to provide users with the necessary credentials for signing payment requests according to the service provider's specifications.
  • [EXTERNAL_DOWNLOADS]: The agent is directed to fetch technical documentation and API reference material from PayerMax's official documentation portal (docs.payermax.com). These downloads are used to ensure that generated code blocks (such as request payloads and field versions) are accurate and up-to-date with the service's requirements.
  • [DATA_EXFILTRATION]: The skill provides detailed instructions on handling sensitive data like merchant private keys and application IDs. It includes defensive instructions for the agent to explicitly warn users against hardcoding secrets and to use standard secure practices such as environment variables and configuration files.
  • [PROMPT_INJECTION]: The skill implements strict instructional constraints (referred to as 'Hard rules' and 'Hard gates') to ensure the agent follows a secure integration path, such as mandating signature verification and query-fallback mechanisms, which reduces the risk of the agent generating insecure code due to user pressure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 07:38 AM
Security Audit — agent-trust-hub — payermax-integration-assistant