software-payments
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references several official SDKs and libraries for payment processing, including
stripe-node,gocardless-nodejs,@mollie/api-client,bullmq, and@apple/app-store-server-library. These are well-known, industry-standard libraries from trusted organizations used for the skill's primary purpose of payment integration. - [COMMAND_EXECUTION]: Instructions in
references/ops-runbook-checkout-errors.mdandreferences/testing-patterns.mdprovidecurlcommands andstripeCLI commands (e.g.,stripe listen,stripe trigger) for troubleshooting, issue reproduction, and local webhook simulation. These are intended for developer operations and testing in local or staging environments. - [INDIRECT_PROMPT_INJECTION]: The skill involves processing data from external sources (payment provider webhooks). It effectively mitigates this vulnerability surface by enforcing signature verification via
stripe.webhooks.constructEvent, validating user identifiers with UUID regex, and recommending structured data schemas for state management to prevent confusion with non-data instructions.
Audit Metadata