stripe-directory
Warn
Audited by Socket on Aug 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core directory/search behavior is broadly consistent with the stated purpose, and Stripe CLI installation looks plausibly legitimate, but the skill overreaches by enabling transitive skill installation and by serving as a gateway into provisioning and transactional actions. The largest concern is the `npx skills add` permission from a docs URL, which is disproportionate for a vendor-directory skill and expands trust beyond the reviewed skill.
Confidence: 83%Severity: 74%
Audit Metadata