salla-app-billing
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows official platform guidelines for app monetization and lifecycle management. No malicious patterns, obfuscation, or unauthorized data access were detected.
- [DATA_EXFILTRATION]: The skill communicates only with official Salla domains, including
api.salla.devanddocs.salla.dev. These network operations are standard for app subscription management and do not involve unauthorized data transit. - [COMMAND_EXECUTION]: Administrative actions are performed using Salla Partners MCP tools (
app_publish,salla_apps). These tools are used for legitimate configuration tasks, such as defining pricing plans and managing webhook URLs. - [PROMPT_INJECTION]: The skill includes proactive security guidance, instructing developers to verify webhook signatures and maintain server-side authority for entitlements to prevent spoofing or injection via external payloads.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive tokens are present in the skill files. It correctly references the use of OAuth access tokens and secure handling of signing secrets.
Audit Metadata