Stripe Payments

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The business purpose is coherent for a Stripe payments skill, and the examples align with official Stripe APIs, but the declared 'payments-mcp' server is not verified as Stripe-owned and introduces an unclear intermediary for sensitive financial actions and credentials. No direct malware or exfiltration is shown, yet the combination of ambiguous MCP provenance and autonomous payment operations makes this medium risk rather than benign.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Jun 3, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills-hub%2Fstripe-payments%2F@964617aadbfcad7f26d68884da7d793a5de7fd5a
Security Audit — socket — Stripe Payments