sales-snipcart

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate documentation and integration recipes for the Snipcart platform, including the requirement for server-side price validation to prevent tampering.
  • [SAFE]: All external URL references target official Snipcart domains (app.snipcart.com) or the documented official hosted MCP server on Microsoft Azure (snipcart-mcp.azurewebsites.net). These are treated as legitimate vendor resources.
  • [SAFE]: Code recipes for Python/Flask follow security best practices, such as verifying webhook authenticity via token-callback and managing credentials using environment variables rather than hardcoding them.
  • [SAFE]: No prompt injection, obfuscation, or unauthorized data exfiltration patterns were detected. The skill's instructions are consistent with its stated purpose of assisting with Snipcart implementations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:16 PM
Security Audit — agent-trust-hub — sales-snipcart