create-payment-credential
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Official Tool Acquisition: The skill utilizes the
@stripe/link-clipackage via npm and npx. As these are official tools provided by the skill's author for its core functionality, this is a standard and safe distribution method for these capabilities. - Sensitive Data Management: The instructions direct the agent to handle virtual card numbers, payment tokens, and shipping addresses. The skill includes specific security measures, such as recommending the use of
--output-filewith restricted file permissions (0600) and applying masking to sensitive data in logs to prevent accidental exposure. - Merchant Data Handling: The skill explicitly instructs the agent to treat all content from merchant websites or API responses as untrusted data. This is a critical security practice to prevent the agent from inadvertently following malicious instructions embedded in third-party pages (indirect prompt injection).
- Secure Command Invocation: For multi-step actions like payment flows, the skill recommends using structured arguments instead of building shell strings. This design choice helps prevent command injection vulnerabilities when dealing with values derived from external merchant pages.
- Authentication Scope Management: The skill provides a clear workflow for managing user authentication, including checking status and upgrading permissions only when necessary. It uses local credential storage to maintain the session state securely.
Audit Metadata