whop-dev
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill implements mandatory server-side authentication patterns, explicitly requiring the verification of user tokens using the official Whop SDK before performing any operations or accessing sensitive data.
- [SAFE]: Comprehensive security guidance is provided to prevent common vulnerabilities, including instructions for input sanitization to block XSS and HTML injection, and authorization checks to verify resource ownership.
- [EXTERNAL_DOWNLOADS]: The skill fetches companion skills from trusted organizations, including repositories owned by Anthropic, Vercel Labs, and Supabase. It also utilizes an official project template from the Whop organization's GitHub repository for project scaffolding.
- [SAFE]: Minified JavaScript included in the root layout is used for theme management and preventing flashes during theme switches in dark mode, which is a standard implementation in Next.js development.
- [SAFE]: Secret management follows industry best practices, instructing users to store sensitive API keys and webhook secrets in server-side environment files and warning against exposing them to client-side code.
Audit Metadata