click-integration

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides detailed specifications and code examples for implementing server-side callback endpoints (SHOP API) that ingest data from the Click payment system via HTTP POST requests.
  • Ingestion points: Prepare and Complete callback handlers described in references/02-shop-api-requests.md process external parameters such as merchant_trans_id, amount, and error_note.
  • Boundary markers: The implementation guidelines require verification of a sign_string hash using a shared secret key, providing a cryptographic boundary for the incoming data.
  • Capability inventory: The skill involves database interactions, such as creating payment records and updating order statuses, as well as fulfillment logic.
  • Sanitization: Provided examples demonstrate basic validation of amounts and transaction identifiers, although users must ensure full sanitization if this data is used in further automated agent workflows.
  • [EXTERNAL_DOWNLOADS]: The skill references multiple external resources to facilitate integration.
  • Fetches official SDKs and implementation examples from the vendor's GitHub organization (click-llc).
  • Provides links to community-maintained Node.js and TypeScript integration examples on GitHub from various authors.
  • Includes direct download links for testing software and CMS plugins hosted on the vendor's official documentation domain docs.click.uz.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:15 PM
Security Audit — agent-trust-hub — click-integration