click-integration
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides detailed specifications and code examples for implementing server-side callback endpoints (SHOP API) that ingest data from the Click payment system via HTTP POST requests.
- Ingestion points: Prepare and Complete callback handlers described in
references/02-shop-api-requests.mdprocess external parameters such asmerchant_trans_id,amount, anderror_note. - Boundary markers: The implementation guidelines require verification of a
sign_stringhash using a shared secret key, providing a cryptographic boundary for the incoming data. - Capability inventory: The skill involves database interactions, such as creating payment records and updating order statuses, as well as fulfillment logic.
- Sanitization: Provided examples demonstrate basic validation of amounts and transaction identifiers, although users must ensure full sanitization if this data is used in further automated agent workflows.
- [EXTERNAL_DOWNLOADS]: The skill references multiple external resources to facilitate integration.
- Fetches official SDKs and implementation examples from the vendor's GitHub organization (
click-llc). - Provides links to community-maintained Node.js and TypeScript integration examples on GitHub from various authors.
- Includes direct download links for testing software and CMS plugins hosted on the vendor's official documentation domain
docs.click.uz.
Audit Metadata