agent-stripe

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and requested Stripe access are broadly coherent, and its safety guidance is sensible, but the core dependency trust is weak: it requires opaque local binaries with no verified provenance in the provided evidence. Because those binaries handle Stripe credentials and can optionally send traffic to an overridden base URL, the skill carries high security risk despite no clear proof of malicious intent.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Jul 15, 2026, 04:26 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-stripe%2F@cc1b7ca56c053cba54e17011004323d2063d2764a4316500dd9f26c31b743819
Security Audit — socket — agent-stripe