create-payment-credential
Warn
Audited by Socket on Sep 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is coherent with its stated purpose and uses an official Stripe/Link CLI, so it is not malware and not a deceptive credential harvester. However, it is inherently high risk because it authorizes an AI agent to make real purchases, handle sensitive payment credentials, automate checkout interactions, and send agent-only reports; classify as SUSPICIOUS/high-risk but not malicious.
Confidence: 88%Severity: 72%
Audit Metadata