extension-stripe

Warn

Audited by Socket on Aug 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core payment capability is coherent with the stated Stripe purpose and the data flow appears intended for Stripe, but the skill carries medium supply-chain risk because it is installed transitively from a GitHub skills repo and relies on a non-reviewable prefabricated Stripe module. Credential scope is proportionate, yet the raw Stripe secret key handling and opaque module reduce assurance.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Aug 17, 2026, 03:39 PM
Package URL
pkg:socket/skills-sh/caffeinelabs%2Fskills%2Fextension-stripe%2F@855fb20525f7fc88f7566a8e07bd4da1763126ca
Security Audit — socket — extension-stripe