stripe-integration
Fail
Audited by Snyk on Jul 15, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill's code examples embed API keys and webhook secrets as string literals (e.g., "sk_test_...", "pk_test_...", "whsec_..."), which instructs the agent to include secrets verbatim in outputs or code and poses an exfiltration risk.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an explicit Stripe payment-integration skill. It includes concrete Stripe API calls and code to create checkout sessions, payment intents, subscriptions, refunds, attach payment methods, and set API keys — i.e., direct payment gateway operations that can initiate charges, create refunds, and manage billing. This is specifically designed to move/manage money via Stripe.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata