skills/stripe/ai/stripe-apps/Gen Agent Trust Hub

stripe-apps

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution via CLI Tools: The skill guides the agent to use command-line tools to perform tasks such as scaffolding new projects and building assets. These actions are standard for the development lifecycle and involve executing binaries on the host system.
  • Automated Feedback Submission: The instructions include a step to submit feedback via a CLI command. This command uses parameters generated from the session's context to provide information about the build process.
  • External Dependency Management: The workflow involves downloading plugins and libraries from external registries to set up the development environment, which is a routine part of modern software projects.
  • Indirect Prompt Injection Surface: The skill uses an initial discovery process to gather requirements from the user (found in SKILL.md and references/discovery.md). These inputs influence the generation of project files and the retrieval of documentation via system capabilities like shell execution and network fetching. No explicit boundary markers or sanitization steps are specified for these data ingestion points.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 08:19 AM
Security Audit — agent-trust-hub — stripe-apps