salla-app-billing

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows official platform guidelines for app monetization and lifecycle management. No malicious patterns, obfuscation, or unauthorized data access were detected.
  • [DATA_EXFILTRATION]: The skill communicates only with official Salla domains, including api.salla.dev and docs.salla.dev. These network operations are standard for app subscription management and do not involve unauthorized data transit.
  • [COMMAND_EXECUTION]: Administrative actions are performed using Salla Partners MCP tools (app_publish, salla_apps). These tools are used for legitimate configuration tasks, such as defining pricing plans and managing webhook URLs.
  • [PROMPT_INJECTION]: The skill includes proactive security guidance, instructing developers to verify webhook signatures and maintain server-side authority for entitlements to prevent spoofing or injection via external payloads.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive tokens are present in the skill files. It correctly references the use of OAuth access tokens and secure handling of signing secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 01:22 PM
Security Audit — agent-trust-hub — salla-app-billing