mcp-stripe

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions provide a shell command for the user to configure the Stripe MCP server connection within the Claude CLI environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources including Stripe API search results and official documentation, creating a potential surface for indirect prompt injection.
  • Ingestion points: search_stripe_resources, search_stripe_documentation, and input files (01-input/goal.md).
  • Boundary markers: The skill mandates a "Dangerous Action Handling Flow" requiring explicit user confirmation before executing financial operations.
  • Capability inventory: Includes financial tools such as create_refund, cancel_subscription, and update_dispute.
  • Sanitization: Relies on explicit instructional guardrails and a mandatory human-in-the-loop confirmation cycle for all high-impact actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 04:34 AM
Security Audit — agent-trust-hub — mcp-stripe