jp-architecture

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were detected across the skill's 26 files.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates excellent security posture regarding secrets. It explicitly forbids recording API keys or webhook passwords in any generated documents or logs, mandating the use of environment variables and the jp-executor skill for credential handling.
  • [EXTERNAL_DOWNLOADS]: Documentation fetching is limited to official and whitelisted Juspay domains (e.g., juspay.io, juspay.in), preventing the ingestion of untrusted or malicious external content.
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration mechanisms were found. Live account data access is optional, user-authorized, and conducted through secure, auth-guarded MCP tools.
  • [PROMPT_INJECTION]: The skill uses a disciplined, step-by-step 'micro-file' architecture that focuses on grounding facts in official documentation, which helps mitigate the risk of instructions being overridden by external input in the processed PRD files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 09:39 AM
Security Audit — agent-trust-hub — jp-architecture