create-payment-credential
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-aligned and uses an official same-org Stripe npm package, so it does not show clear malware or credential-harvesting deception. But it is inherently high risk because it enables autonomous financial transactions, processes card-equivalent credentials and shipping PII, can write card data locally, and includes agent-only reporting; overall this is best classified as suspicious/high-risk rather than malicious.
Confidence: 91%Severity: 78%
Audit Metadata