agent-stripe
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and requested Stripe access are broadly coherent, and its safety guidance is sensible, but the core dependency trust is weak: it requires opaque local binaries with no verified provenance in the provided evidence. Because those binaries handle Stripe credentials and can optionally send traffic to an overridden base URL, the skill carries high security risk despite no clear proof of malicious intent.
Confidence: 86%Severity: 82%
Audit Metadata