shoplazza-billing
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong safety practices for financial operations. It explicitly instructs the agent to use
--dry-runfirst, restate all charge details (name, price, type, return URL) to the user, and wait for human confirmation before execution. This aligns with best practices for tools that move real money. - [SAFE]: No obfuscation, data exfiltration, or unauthorized command execution patterns were found. The CLI commands used (
billing one-time create,billing recurring list, etc.) are part of the author's own official toolset ('shoplazza' CLI). - [SAFE]: The skill includes instructions to ask the user for missing fields rather than fabricating data, reducing the risk of accidental or incorrect charges.
- [SAFE]: The authorization section provides domain-specific guidance regarding Shoplazza's internal permission model, which is consistent with documented developer workflows for this platform.
Audit Metadata