payload

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation repository for Payload CMS development, containing valid TypeScript patterns and architectural guidance.\n- [SAFE]: All external resource links target official Payload CMS documentation, GitHub repositories, or well-known development services (e.g., Vercel, Stripe, AWS, MongoDB), which are considered trusted sources.\n- [SAFE]: The skill includes proactive security education, such as highlighting the risks of bypassing access control in the Local API and providing atomic transaction patterns to prevent data corruption.\n- [SAFE]: No obfuscation, hardcoded credentials, unauthorized command execution, or data exfiltration patterns were found within the skill instructions or reference files.\n- [SAFE]: The skill handles untrusted data indirectly by providing guidance on how the agent should process project configuration files (payload.config.ts, collection files) and user queries. While there are no explicit prompt boundary markers, the skill's purpose is purely informational and educational.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 03:33 PM
Security Audit — agent-trust-hub — payload