check-stripe

Warn

Audited by Snyk on Feb 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly specific to a payment gateway (Stripe). It references Stripe SDK usage, secret/publishable keys, Stripe CLI commands, webhook signing, and spawns a "stripe-auditor" agent; it also links to related primitives including /fix-stripe and /stripe (full Stripe lifecycle management). Although the described primitive's main function is auditing/reporting, the skill is clearly and specifically designed around a payment gateway API (Stripe) rather than being a generic tool — and it references endpoints that imply operational changes. Per the rule to flag specific payment-gateway tools/APIs, this qualifies as Direct Financial Execution risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 05:09 PM