stripe
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s Stripe-management purpose matches its capabilities, and there is no remote installer or hidden executable payload. However, the data flow is not direct to Stripe: all API calls and payment operations are routed through Maton-controlled gateway/control domains that hold and inject OAuth credentials server-side. That third-party mediation is disproportionate compared with a normal direct Stripe integration and creates man-in-the-middle/credential custody risk, especially for financial actions. Not confirmed malware, but the proxy-based architecture makes this higher-risk than a standard vendor-direct Stripe skill.
Confidence: 89%Severity: 66%
Audit Metadata