jp-architecture
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were detected across the skill's 26 files.
- [CREDENTIALS_UNSAFE]: The skill demonstrates excellent security posture regarding secrets. It explicitly forbids recording API keys or webhook passwords in any generated documents or logs, mandating the use of environment variables and the
jp-executorskill for credential handling. - [EXTERNAL_DOWNLOADS]: Documentation fetching is limited to official and whitelisted Juspay domains (e.g., juspay.io, juspay.in), preventing the ingestion of untrusted or malicious external content.
- [DATA_EXFILTRATION]: No unauthorized data exfiltration mechanisms were found. Live account data access is optional, user-authorized, and conducted through secure, auth-guarded MCP tools.
- [PROMPT_INJECTION]: The skill uses a disciplined, step-by-step 'micro-file' architecture that focuses on grounding facts in official documentation, which helps mitigate the risk of instructions being overridden by external input in the processed PRD files.
Audit Metadata