stripe

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s Stripe-management purpose matches its capabilities, and there is no remote installer or hidden executable payload. However, the data flow is not direct to Stripe: all API calls and payment operations are routed through Maton-controlled gateway/control domains that hold and inject OAuth credentials server-side. That third-party mediation is disproportionate compared with a normal direct Stripe integration and creates man-in-the-middle/credential custody risk, especially for financial actions. Not confirmed malware, but the proxy-based architecture makes this higher-risk than a standard vendor-direct Stripe skill.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/craftos-dev%2Fcraftbot%2Fstripe%2F@b2d353e17ed69aa2861bae6aa34ae19f0870f3267dfae6b618a36cd98061a508
Security Audit — socket — stripe