stripe
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill emphasizes security best practices for environment variable management, providing clear distinctions between server-side secrets and client-side publishable keys to prevent credential leakage in Vite-based applications.\n- [SAFE]: The webhook handler implementation follows the industry standard of verifying event signatures using the raw request body before processing, effectively mitigating potential spoofing attacks.\n- [COMMAND_EXECUTION]: The documentation includes various shell commands for the Stripe CLI and standard Unix utilities to automate product creation and secret management tasks.\n- [SAFE]: The skill promotes a 'One Stripe customer per Org' architecture and includes logic to prevent duplicate subscriptions by checking the database state before initiating checkout sessions.
Audit Metadata