stripe-connect

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's basic purpose is legitimate, and its stated data flow to Stripe is proportionate, but it instructs users to paste high-value Stripe credentials directly into chat and hands them to a custom unverifiable helper script. No clear malware or third-party credential proxy is shown, yet the credential-handling model is unnecessarily risky for a connection helper.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
Apr 17, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/CreminiAI%2Fcremini-skills%2Fstripe-connect%2F@ed90168c6b638af626d9b5665285a01501860e7a