spree-payments
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as an educational resource for Spree's payment system, covering state machines, payment methods, and sessions. No malicious instructions, obfuscation, or data exfiltration patterns were detected.
- [CREDENTIALS_UNSAFE]: The documentation includes a security warning noting that payment gateway preferences (including secret keys) are stored as plain text in the database by the platform. It correctly advises users to treat database backups as containing live secrets. This is presented as an architectural advisory for users of the platform.
- [COMMAND_EXECUTION]: Provides standard developer commands for the Spree CLI and Rails environment, such as adding gems and running migrations. These are typical operations for the described use case.
- [EXTERNAL_DOWNLOADS]: Includes a reference to the official Spree Stripe integration on GitHub. As this belongs to the well-known vendor of the platform being documented, it is a trusted source.
Audit Metadata