stripe-payment-links
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill delegates sensitive operations and credential management to a dedicated platform (Membrane), ensuring that Stripe API keys and tokens are never exposed to the agent or stored in local configuration files.
- [EXTERNAL_DOWNLOADS]: The instructions involve installing the official vendor CLI tool (@membranehq/cli) from the public npm registry. This is a legitimate and necessary dependency for the skill's integration features.
- [COMMAND_EXECUTION]: The skill uses shell commands via the Membrane CLI to facilitate payment link management. All commands are standard for the described workflow and do not involve unauthorized privilege escalation or suspicious behavior.
Audit Metadata