stripe-payment-links

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is coherent with its stated purpose, but it introduces a meaningful trust boundary by routing Stripe authentication and data access through Membrane rather than Stripe directly. The main concerns are third-party intermediary access, external CLI dependence, and unpinned `@latest` installs; this is suspicious from a data-flow perspective but not confirmed malicious.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
May 7, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstripe-payment-links%2F@046612dd868f98517f82cc7055cfc0f3c2b0ae69