integrate-solvapay-sdk

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified in the analysis of the skill files.\n- [EXTERNAL_DOWNLOADS]: The skill references the installation of official SDK packages and documentation from the vendor.\n
  • Documentation is fetched from the official domain docs.solvapay.com.\n
  • Node.js packages include @solvapay/server, @solvapay/next, @solvapay/react, @solvapay/auth, and @solvapay/react-supabase, which are vendor-owned resources according to the skill author context.\n
  • The skill also mentions @supabase/supabase-js, which is a well-known and trusted service library.\n- [CREDENTIALS_UNSAFE]: The skill does not contain hardcoded secrets and includes explicit instructions to keep sensitive API keys on the server and out of client-side code bundles (e.g., advising against using NEXT_PUBLIC_ prefixes for secrets).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 10:03 PM