agent-stripe
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s business purpose is coherent, and its Stripe-focused commands are proportionate to payment investigation. However, it relies on external CLIs whose provenance was not verified and explicitly routes Stripe API credentials into one of those binaries; combined with endpoint override support, this makes the skill high risk despite no confirmed malicious behavior.
Confidence: 76%Severity: 84%
Audit Metadata