paystack-transactions

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and provides code examples using the official Paystack client-side library @paystack/inline-js. This is a standard dependency for integrating Paystack payments.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data, specifically transaction references received from URL query parameters and user-supplied email addresses.
  • Ingestion points: Data enters the application via the reference parameter in PaymentCallback (SKILL.md) and user input in PayButton (SKILL.md).
  • Boundary markers: The instructions explicitly warn developers to "NEVER trust [client-side callbacks] alone" and to perform server-side verification.
  • Capability inventory: The skill uses a paystackRequest helper to perform network operations to Paystack's API endpoints.
  • Sanitization: The code examples correctly use encodeURIComponent(reference) to prevent injection into URL paths and convert numerical amounts to integer subunits (kobo) before processing.
  • [SAFE]: The code snippets provided follow security best practices, including mandatory server-side verification of payment status and validation of transaction amounts to prevent price manipulation attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:06 PM
Security Audit — agent-trust-hub — paystack-transactions