stripe-automation

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The artifact is an automation skill that purposefully delegates Stripe operations to a third-party MCP (Rube/Composio) and its stripe toolkit. There is no direct evidence of malware or obfuscated malicious code in the provided file, and no hardcoded secrets. The principal security issues are supply-chain and operational: credential custody by the MCP, potential logging/exposure of PII/payment data, and the ability to perform high-impact financial operations without prescribed confirmation controls. These require explicit trust in the MCP operator and implementing mitigations (least-privilege scopes, audit logging, manual confirmations) before use in sensitive environments. This is a medium-risk integration pattern rather than confirmed malicious code.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Skills%2Fstripe-automation%2F@651493ab184cdee3a0196fa8007232eba33a0b8c