paystack-setup
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill correctly demonstrates how to handle secrets using environment variables. It uses safe placeholders like
sk_test_xxxxxandpk_test_xxxxxfor documentation purposes and provides explicit warnings to never include secret keys in client-side code or public repositories. It also correctly advises adding.envfiles to.gitignoreto prevent accidental credential leakage. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to install
@paystack/inline-jsfrom the official npm registry, which is a standard and safe dependency for Paystack integrations. - [COMMAND_EXECUTION]: The provided bash commands are standard package installation routines (
npm install,pnpm add,yarn add) using well-known packages. - [DATA_EXFILTRATION]: All network operations target the official Paystack API endpoint (
https://api.paystack.co). There are no signs of data being sent to unauthorized third-party domains. - [SAFE]: The skill follows security best practices, such as recommending server-side validation of transactions, subunit conversion to avoid floating-point errors, and proper error handling classes for API responses.
Audit Metadata