paystack-subscriptions
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from the external Paystack API, which serves as a potential ingestion point for untrusted content that could influence agent behavior.
- Ingestion points: Data returned from the
paystackRequesthelper method across various endpoints such as subscription fetches and plan listings inSKILL.md. - Boundary markers: The instructions do not provide explicit delimiters or instructions for the agent to differentiate between trusted system instructions and untrusted data from the API responses.
- Capability inventory: The skill possesses the capability to perform network operations, including POST and GET requests to manage financial subscriptions.
- Sanitization: There is no documentation of sanitization or validation logic to filter potentially malicious strings (e.g., in plan names or customer metadata) before the agent processes the API output.
Audit Metadata