visa-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references external implementation details and code examples hosted on a domain controlled by the skill author.
- Evidence: The documentation directs the agent to fetch implementation context from
https://sandbox.mcp.visa.com/mcp/doc/llms.txt. - Source Recognition: The domain
mcp.visa.comis an official resource of Visa, matching the skill's author context. - [CREDENTIALS_UNSAFE]: The integration guide provides clear security instructions for managing sensitive data.
- Evidence: It explicitly advises against hardcoding credentials in source code and recommends the use of environment variables or dedicated secret managers.
Audit Metadata