kinde-billing

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust authorization model, explicitly labeling high-impact mutations (such as Stripe connection, plan publishing, and meter writes) as 'planned' until a user provides explicit authorization and reviews the billing contract.
  • [SAFE]: All external references and API specifications point to official Kinde domains and verified GitHub repositories, adhering to established safe practices for documentation and configuration sources.
  • [SAFE]: The skill enforces a clear separation between test and production environments, requiring the use of non-production Kinde environments and Stripe test mode by default to prevent accidental data exposure or financial impact.
  • [SAFE]: Technical instructions for API usage and webhook handling follow industry-standard security practices, such as JWT signature verification via JWKS and idempotency checks using stable event headers.
  • [SAFE]: No obfuscation, hidden instructions, or unauthorized remote code execution patterns were detected across the skill's components.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:07 PM
Security Audit — agent-trust-hub — kinde-billing