link-cli
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and capabilities are internally consistent: this is an official Stripe Link wallet skill built around Stripe's published CLI and device auth flow, not a disguised credential stealer. The main risk is not malware but impact: the skill lets an agent initiate real payments, reveal one-time card credentials, and send value to merchant endpoints, with persistent local auth and optional endpoint overrides increasing exposure if misused or tampered with.
Confidence: 89%Severity: 74%
Audit Metadata