skills/stripe/ai/stripe-directory/Gen Agent Trust Hub

stripe-directory

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [External Service Interaction]: The skill is designed to search and interact with a directory of services via the official vendor CLI. It references https://stripe.directory and https://docs.stripe.com for documentation and configuration, which is standard behavior for service discovery.
  • [Tool Installation and Execution]: The skill allows for the installation and upgrading of the official vendor CLI using brew and the addition of skills via npx. These commands are restricted to the vendor's official packages and repositories (e.g., stripe/stripe-cli/stripe), aligning with secure software management practices.
  • [Provisioning Logic]: The skill contains instructions for handing off provisioning tasks to a secondary skill (stripe-projects) if requested by the user. It includes a fallback command to install this secondary skill from the official GitHub repository (github.com/stripe/ai), which is a routine extension mechanism for complex workflows.
  • [Data Handling]: The skill explicitly instructs the agent to ask the user for approval before any transactions (payments or donations) and only to request credentials when necessary for authentication, which follows the principle of user consent and least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 06:44 AM
Security Audit — agent-trust-hub — stripe-directory