Back to skill

Security audit

Stripe

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Stripe administration skill with powerful financial actions, but the behavior is documented and requires explicit user approval for writes.

Install only if you want an agent to administer Stripe. Use the least-privileged Stripe/Maton connection available, prefer test mode, always verify the Maton-Connection account, and require explicit confirmation before charges, refunds, invoice payment/finalization, payment method changes, deletions, or subscription changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill metadata says access is limited to customers, subscriptions, invoices, products, prices, and payments, but the documented API reference also includes balance, balance transactions, charges, payment methods, coupons, and refunds. This mismatch broadens the apparent operational scope of a write-capable financial skill and can mislead operators or downstream policy engines about what actions the skill enables.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.