crypto-payments
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted external data via payment webhooks to trigger financial actions.\n
- Ingestion points: The webhook POST endpoint (
/api/billing/crypto/webhook) receives JSON payloads from the external payment gateway.\n - Boundary markers: The implementation mandates proxy-aware IP allowlisting and cryptographic signature verification (MD5 of Base64-encoded payload) before processing.\n
- Capability inventory: Upon successful verification, the skill performs database writes to update payment statuses (
db.cryptoPayment.updateMany), credits user account balances (creditAccountPurchasedTokens), and sends user notifications.\n - Sanitization: Payload data is validated against specific types, and status strings are mapped to a strict internal enum before being used in application logic.\n- [EXTERNAL_DOWNLOADS]: The skill references an external security script within the vendor's namespace.\n
- Evidence: Mentions
plugins/sheleg-dev/hooks/money-gate.jsas a PreToolUse hook for enforcing billing safety and tool execution restrictions. This script is identified as a resource provided by the skill author ('ssheleg').
Audit Metadata