stripe-revenue

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent, and the visible commands are narrowly scoped to Stripe revenue reporting, but the mandatory dependency on a nonstandard stripe-connect prerequisite is not aligned with Stripe's official CLI naming or documented install path. Because the skill also instructs loading another skill, trust is transitive and provenance is unclear. No confirmed malicious behavior is visible in this snippet, but install trust and data-flow certainty are insufficient for a benign classification.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 17, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/CreminiAI%2Fcremini-skills%2Fstripe-revenue%2F@3c51f4672f33d2cb732704cdc2d5b149293864e5