check-stripe
Warn
Audited by Snyk on Feb 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly specific to a payment gateway (Stripe). It references Stripe SDK usage, secret/publishable keys, Stripe CLI commands, webhook signing, and spawns a "stripe-auditor" agent; it also links to related primitives including /fix-stripe and /stripe (full Stripe lifecycle management). Although the described primitive's main function is auditing/reporting, the skill is clearly and specifically designed around a payment gateway API (Stripe) rather than being a generic tool — and it references endpoints that imply operational changes. Per the rule to flag specific payment-gateway tools/APIs, this qualifies as Direct Financial Execution risk.
Audit Metadata