stripe-subscriptions

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated Stripe billing purpose is coherent, but the skill is largely a remote-content loader that pulls mutable instructions from fullstackrecipes.com and leads to transitive skill installation. No direct credential theft or exfiltration is visible here, yet install-trust and remote-instruction risks make it higher than a normal documentation skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/felipeangeli%2Fskills%2Fstripe-subscriptions%2F@eeecf60d919526db6e63ea9634a3dd506d23a8d7e1bfb1c6bae4109aa5c6384b
Security Audit — socket — stripe-subscriptions