portaly-payment
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides explicit security guidelines for the safe management of sensitive material like API keys and callback secrets, including the use of environment variables and the
.gitignorefile to prevent accidental disclosure. - [SAFE]: Human-in-the-loop guardrails are enforced for high-risk operations such as managing recurring subscriptions or creating production-level plans, ensuring the user is aware of financial impacts.
- [SAFE]: Included utility scripts for signature verification in the
scripts/directory follow cryptographic best practices, utilizing constant-time comparison functions to prevent timing side-channel attacks. - [SAFE]: All external references and API endpoints target the official vendor domain and are consistent with the skill's stated purpose of facilitating payment integrations.
Audit Metadata