stripe-stack
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides integration patterns for well-known and trusted platforms including Stripe, Supabase, and Vercel (Next.js), facilitating standard e-commerce and SaaS billing functionalities.- [SAFE]: Webhook implementation templates prioritize security by enforcing signature verification via the official Stripe SDK and implementing database-level idempotency checks to mitigate replay attacks and duplicate event processing.- [SAFE]: The skill provides clear and correct guidance on credential management, emphasizing the use of environment variables for secrets like the STRIPE_SECRET_KEY and SUPABASE_SERVICE_ROLE_KEY while warning against hardcoding sensitive data.- [SAFE]: Administrative scripts, such as the Python-based product migration tool, use official libraries and follow standard patterns for environment transition without introducing hidden or malicious execution vectors.
Audit Metadata