create-payment-credential

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and uses an official same-org Stripe npm package, so it does not show clear malware or credential-harvesting deception. But it is inherently high risk because it enables autonomous financial transactions, processes card-equivalent credentials and shipping PII, can write card data locally, and includes agent-only reporting; overall this is best classified as suspicious/high-risk rather than malicious.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Sep 16, 2026, 01:10 PM
Package URL
pkg:socket/skills-sh/stripe%2Flink-cli%2Fcreate-payment-credential%2F@3d18e0768a4d3265af60af38d37027fb33fb6c2c57c75e4ed6d4bcb7b8c32e57
Security Audit — socket — create-payment-credential