stripe
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality security guidance for Stripe integrations, including production checklists and hardening instructions.
- [COMMAND_EXECUTION]: The skill includes
scripts/verify.sh, which is a static analysis tool for linting the user's project. It identifies security risks such as hardcoded keys or unverified webhooks. The script is read-only, operates locally using standard system utilities (find,grep), and does not exhibit malicious behavior. - [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external data via webhooks (a potential ingestion point for untrusted data), it explicitly mitigates this risk by requiring cryptographic signature verification using
stripe.webhooks.constructEventbefore any data is processed or stored. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill correctly advises against hardcoding sensitive credentials (
STRIPE_SECRET_KEY) and provides a checklist to ensure developers use restricted API keys and environment variables.
Audit Metadata