stripe-billing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and provides instructions for installing official Stripe and Claude tooling, such as @stripe/cli from the NPM registry and the official Stripe plugin for Claude Code. These references target well-known and trusted organizations.
  • [COMMAND_EXECUTION]: The documentation in fixtures/README.md instructs users to run node assert-money-invariants.mjs to execute the provided test suite. This script is a local utility shipped with the skill for implementation verification and does not perform dangerous operations.
  • [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process external webhook events from Stripe, it inherently defines an ingestion surface for untrusted data. However, the documentation emphasizes strong security controls, including mandatory signature verification using stripe.webhooks.constructEvent and idempotent processing logic to mitigate risks. The provided reference implementation acts on an in-memory store and does not expose sensitive system capabilities to the processed data.
  • Ingestion points: Webhook payloads are processed via the deliver(event) entry point in reference-handler.mjs and the POST route example in SKILL.md.
  • Boundary markers: The implementation utilizes stripe.webhooks.constructEvent with a secret key for integrity checking and identifies individual events by a unique event.id.
  • Capability inventory: The provided scripts are limited to managing an in-memory data store for testing and do not perform file system writes, network requests (beyond documentation examples), or subprocess execution.
  • Sanitization: Webhook payloads are verified against the signing secret before processing.
  • [SAFE]: The skill represents a best-practice implementation for financial integrations. It correctly handles sensitive credential management by advising against hardcoding keys and suggesting the use of environment variables or secret vaults. It also includes comprehensive logic for handling complex billing scenarios such as flexible vs. classic billing modes and cumulative refund tracking.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:58 AM
Security Audit — agent-trust-hub — stripe-billing