stripe-app-builder

Warn

Audited by Socket on Jun 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches Stripe integration guidance and it mostly follows official Stripe best practices, so it does not look malicious. The main risk is trust in opaque `cofounder run` platform commands that may handle Stripe credentials and production billing actions without public provenance or verifiable implementation details in the skill itself.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 9, 2026, 09:35 PM
Package URL
pkg:socket/skills-sh/jpoindexter%2FTHEFT-AI%2Fstripe-app-builder%2F@ce51c2e31d8ecd4807bf8c0a6c1f05a7d33fee99
Security Audit — socket — stripe-app-builder