software-payments

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several official SDKs and libraries for payment processing, including stripe-node, gocardless-nodejs, @mollie/api-client, bullmq, and @apple/app-store-server-library. These are well-known, industry-standard libraries from trusted organizations used for the skill's primary purpose of payment integration.
  • [COMMAND_EXECUTION]: Instructions in references/ops-runbook-checkout-errors.md and references/testing-patterns.md provide curl commands and stripe CLI commands (e.g., stripe listen, stripe trigger) for troubleshooting, issue reproduction, and local webhook simulation. These are intended for developer operations and testing in local or staging environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing data from external sources (payment provider webhooks). It effectively mitigates this vulnerability surface by enforcing signature verification via stripe.webhooks.constructEvent, validating user identifiers with UUID regex, and recommending structured data schemas for state management to prevent confusion with non-data instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-payments