stripe-billing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and provides instructions for installing official Stripe and Claude tooling, such as
@stripe/clifrom the NPM registry and the official Stripe plugin for Claude Code. These references target well-known and trusted organizations. - [COMMAND_EXECUTION]: The documentation in
fixtures/README.mdinstructs users to runnode assert-money-invariants.mjsto execute the provided test suite. This script is a local utility shipped with the skill for implementation verification and does not perform dangerous operations. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process external webhook events from Stripe, it inherently defines an ingestion surface for untrusted data. However, the documentation emphasizes strong security controls, including mandatory signature verification using
stripe.webhooks.constructEventand idempotent processing logic to mitigate risks. The provided reference implementation acts on an in-memory store and does not expose sensitive system capabilities to the processed data. - Ingestion points: Webhook payloads are processed via the
deliver(event)entry point inreference-handler.mjsand thePOSTroute example inSKILL.md. - Boundary markers: The implementation utilizes
stripe.webhooks.constructEventwith a secret key for integrity checking and identifies individual events by a uniqueevent.id. - Capability inventory: The provided scripts are limited to managing an in-memory data store for testing and do not perform file system writes, network requests (beyond documentation examples), or subprocess execution.
- Sanitization: Webhook payloads are verified against the signing secret before processing.
- [SAFE]: The skill represents a best-practice implementation for financial integrations. It correctly handles sensitive credential management by advising against hardcoding keys and suggesting the use of environment variables or secret vaults. It also includes comprehensive logic for handling complex billing scenarios such as flexible vs. classic billing modes and cumulative refund tracking.
Audit Metadata