stripe

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill emphasizes security best practices for environment variable management, providing clear distinctions between server-side secrets and client-side publishable keys to prevent credential leakage in Vite-based applications.\n- [SAFE]: The webhook handler implementation follows the industry standard of verifying event signatures using the raw request body before processing, effectively mitigating potential spoofing attacks.\n- [COMMAND_EXECUTION]: The documentation includes various shell commands for the Stripe CLI and standard Unix utilities to automate product creation and secret management tasks.\n- [SAFE]: The skill promotes a 'One Stripe customer per Org' architecture and includes logic to prevent duplicate subscriptions by checking the database state before initiating checkout sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 04:15 PM
Security Audit — agent-trust-hub — stripe