paystack-subscriptions

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from the external Paystack API, which serves as a potential ingestion point for untrusted content that could influence agent behavior.
  • Ingestion points: Data returned from the paystackRequest helper method across various endpoints such as subscription fetches and plan listings in SKILL.md.
  • Boundary markers: The instructions do not provide explicit delimiters or instructions for the agent to differentiate between trusted system instructions and untrusted data from the API responses.
  • Capability inventory: The skill possesses the capability to perform network operations, including POST and GET requests to manage financial subscriptions.
  • Sanitization: There is no documentation of sanitization or validation logic to filter potentially malicious strings (e.g., in plan names or customer metadata) before the agent processes the API output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:55 PM
Security Audit — agent-trust-hub — paystack-subscriptions