agent-stripe

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s business purpose is coherent, and its Stripe-focused commands are proportionate to payment investigation. However, it relies on external CLIs whose provenance was not verified and explicitly routes Stripe API credentials into one of those binaries; combined with endpoint override support, this makes the skill high risk despite no confirmed malicious behavior.

Confidence: 76%Severity: 84%
Audit Metadata
Analyzed At
Aug 31, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-stripe%2F@1fbedd0df4bef0d496f8cf44b29d093f1a58b2aba2e228719195fc0f8eff5854
Security Audit — socket — agent-stripe