stripe-subscriptions

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Stripe subscription purpose is plausible, but the skill is mostly a wrapper around mutable third-party remote recipes and introduces transitive skill installation. There is no confirmed malware in the submitted text, but the install trust chain and indirect expansion of capabilities make the skill medium-high risk.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
May 17, 2026, 02:08 AM
Package URL
pkg:socket/skills-sh/marcioaltoe%2Fskills%2Fstripe-subscriptions%2F@ff660de58c25794379949596b26d713a2d4de570
Security Audit — socket — stripe-subscriptions