sales-snipcart
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate documentation and integration recipes for the Snipcart platform, including the requirement for server-side price validation to prevent tampering.
- [SAFE]: All external URL references target official Snipcart domains (app.snipcart.com) or the documented official hosted MCP server on Microsoft Azure (snipcart-mcp.azurewebsites.net). These are treated as legitimate vendor resources.
- [SAFE]: Code recipes for Python/Flask follow security best practices, such as verifying webhook authenticity via token-callback and managing credentials using environment variables rather than hardcoding them.
- [SAFE]: No prompt injection, obfuscation, or unauthorized data exfiltration patterns were detected. The skill's instructions are consistent with its stated purpose of assisting with Snipcart implementations.
Audit Metadata