skills/hit-pay/agent-skills/hitpay/Gen Agent Trust Hub

hitpay

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE] (SAFE): The skill follows security best practices by recommending environment variables (HITPAY_API_KEY, HITPAY_SALT) rather than hardcoding credentials.
  • [SAFE] (SAFE): Webhook verification logic uses crypto.timingSafeEqual and sha256 HMAC, which are industry standards for preventing timing attacks and ensuring data integrity.
  • [EXTERNAL_DOWNLOADS] (SAFE): The skill references the common qrcode package for legitimate client-side QR generation.
  • [COMMAND_EXECUTION] (SAFE): The utility script scripts/verify-webhook.sh is benign and serves only to output boilerplate code samples for developers.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:59 PM