Back to skill

Security audit

Stripe Webhook Replay Lab

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it handles a Stripe webhook secret and temporary response files in ways that deserve review before installation.

Install only if you intend to run a local or staging Stripe webhook replay helper. Use test webhook secrets and non-production payloads, avoid shared or privileged hosts, and review the script before pointing it at any endpoint that can mutate real customer, payment, subscription, or account state.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/replay-stripe-webhook.sh:113
Finding

Stripe webhook secret exposed through process command-line arguments

Content
View full analysis
/cmdline`, subject to the operating system's process visibility and permission configuration. Although the OpenSSL process is short-lived, the operation is repeated for every replay attempt, increasing the opportunity for a local process to observe the argument. The secret authorizes generation of valid Stripe webhook signatures and should not be copied into process arguments. ### Attack Path 1. A legitimate user executes the replay script with a valid Stripe webhook endpoint secret. 2. A local attacker or monitoring process with permission to inspect the user's processes repeatedly enumerates command lines. 3. During an OpenSSL invocation, the attacker captures the value supplied after `-hmac`. 4. The attacker uses the recovered secret to compute HMAC-SHA256 signatures for attacker-controlled Stripe event payloads. 5. The forged requests are sent to an endpoint configured to trust that webhook secret. Exploitation requires local process visibility or an equivalent process-monitoring capability. ### Impact Assessment Disclosure of the endpoint secret allows an attacker to forge webhook signatures accepted by applications using the same secret. The resulting application-level impact depends on the webhook handler's behavior and may includ ...[truncated 319 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/replay-stripe-webhook.sh:117
Finding

Predictable temporary response file permits symlink-based file overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
bash scripts/replay-stripe-webhook.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
bash scripts/replay-stripe-webhook.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
bash scripts/replay-stripe-webhook.sh

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/replay-stripe-webhook.sh (reported line 148)May include surrounding context.

sh
fi
done

rm -f /tmp/stripe-webhook-replay-response.$$ || true

echo ""
echo "Summary: ${ok} passed, ${failed} failed"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly intends to invoke shell capabilities via bash scripts/replay-stripe-webhook.sh, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a governance gap: an agent or platform may execute shell-based behavior without an explicit least-privilege declaration, making review, sandboxing, and policy enforcement harder.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/replay-stripe-webhook.sh (reported line 121)May include surrounding context.

sh
stripe_sig_header="t=${ts},v1=${signature}"

  start_ns="$(date +%s%N)"
  http_code="$(curl -sS -o /tmp/stripe-webhook-replay-response.$$ \
    -w "%{http_code}" \
    --max-time "$REQUEST_TIMEOUT_SECONDS" \
    -X POST "$STRIPE_WEBHOOK_URL" \

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script consumes STRIPE_WEBHOOK_SECRET, which is credential-like sensitive data, but only validates its presence and never warns the user that a secret will be used to sign outbound requests. There is no confirmation prompt, comment/docstring disclosure, or other user-facing notice about handling sensitive credentials in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The curl POST sends the supplied JSON payload and Stripe-Signature header to STRIPE_WEBHOOK_URL, which is a network operation that may transmit user or system data. Although the script prints the target URL and event metadata, it does not explicitly warn the user that payload contents will be sent over the network.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.