mcp-stripe
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions provide a shell command for the user to configure the Stripe MCP server connection within the Claude CLI environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources including Stripe API search results and official documentation, creating a potential surface for indirect prompt injection.
- Ingestion points:
search_stripe_resources,search_stripe_documentation, and input files (01-input/goal.md). - Boundary markers: The skill mandates a "Dangerous Action Handling Flow" requiring explicit user confirmation before executing financial operations.
- Capability inventory: Includes financial tools such as
create_refund,cancel_subscription, andupdate_dispute. - Sanitization: Relies on explicit instructional guardrails and a mandatory human-in-the-loop confirmation cycle for all high-impact actions.
Audit Metadata