create-payment-credential

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Official Vendor Tooling: The skill relies on the @stripe/link-cli, an official package provided by the vendor. This tool is installed or executed using standard Node.js package managers (npm, npx), which is consistent with the skill's purpose of managing Link wallet credentials.
  • Sensitive Data Management: The workflow involves handling payment cards, Shared Payment Tokens (SPTs), and personal shipping information. The instructions include guidelines for the agent to mask sensitive details and use secure local file storage for credential handoff to minimize exposure in logs or transcripts.
  • User-in-the-Loop Security: A core part of the transaction process is the requirement for users to approve spend requests via the Link app. This provides a critical manual checkpoint before any financial transaction is finalized.
  • Automated Payment Processing: The skill includes capabilities to interact with merchant endpoints for programmatic payments (MPP). While this involves processing external data such as merchant headers, the skill directs the agent to evaluate the legitimacy of merchants and respect automated interaction directives like agents.txt.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 12:12 AM
Security Audit — agent-trust-hub — create-payment-credential