stripe-link-cli

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its stated purpose and the Stripe CLI provenance is consistent, but it grants an AI agent high-impact payment capabilities, handles unmasked payment credentials, and adds a transitive installation path through a third-party skills CLI. Data flows are mostly legitimate for Stripe/merchant payments, yet custom base URLs, proxies, local card-file output, and autonomous purchase workflows make the overall risk medium-high rather than benign.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
May 17, 2026, 06:30 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fstripe-link-cli%2F@2df3c3e9824f42609113d6f77ebfa133bf14aea9