Back to skill

Security audit

Stripe Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Stripe payment-integration guide with helper code; it has normal payment/API risks but no evidence of hidden, deceptive, or unrelated behavior.

Install only if you intend to build a Stripe payment flow. Use test-mode keys first, keep Stripe secrets out of client-side code, review any sudo package-install commands before running them, pin dependencies in your app, and add durable database or Redis idempotency for webhook event IDs before using this in production.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/stripe_helpers.py:134
Finding

Webhook events are dispatched without persistent idempotency protection

Content
View full analysis
str: """ Dispatch a Stripe webhook event to the correct handler. Args: event: Parsed event dict from verify_webhook(). handlers: Dict mapping event type → callable(data). e.g. { "checkout.session.completed": my_checkout_handler, "customer.subscription.deleted": my_cancel_handler, } Returns: "handled" if a matching handler was called, "ignored" otherwise. """ event_type = event.get("type", "") data = event.get("data", {}).get("object", {}) handler = handlers.get(event_type) if handler: handler(data) return "handled" return "ignored" ``` The documentation proposes an optional in-memory mechanism, but it is not integrated into the webhook handler: ```python PROCESSED_EVENTS = set() def is_duplicate_event(event_id: str) -> bool: if event_id in PROCESSED_EVENTS: return True PROCESSED_EVENTS.add(event_id) return False ``` ### Technical Analysis Stripe retries webhook deliveries when acknowledgements are delayed, lost, or return an error. A valid event may therefore be delivered more than once. The reusable dispatcher immediately invokes the business handler without checking whether `event["id"]` has already been processed. The example in `SKILL.md` does not resolve this issue because its duplicate-event check is only presented as optional commented guidance. Its process-local `set` would also be insufficient in production: it is lost during restarts and is not shared across application workers or servers. A check followed by a separate insertion can also be su ...[truncated 1390 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:22
Finding

Third-party Python dependencies are installed without version or integrity constraints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/stripe_helpers.py:115
Finding

Malformed webhook payload parsing errors are not handled

Content
View full analysis
dict | None: """ Verify a Stripe webhook signature and return the parsed event dict. Returns None if verification fails. Usage (Flask): payload = request.data sig = request.headers.get("Stripe-Signature") event = verify_webhook(payload, sig) if event is None: return jsonify({"error": "Invalid signature"}), 400 """ try: event = stripe.Webhook.construct_event(payload, sig_header, WEBHOOK_SECRET) return event except stripe.error.SignatureVerificationError: return None ``` ### Technical Analysis The function converts signature-verification failures into a controlled rejection but does not handle malformed payload parsing errors such as `ValueError`. A public webhook endpoint receives attacker-controlled request bodies, so invalid JSON or otherwise malformed event data must be treated as an expected client error. If `stripe.Webhook.construct_event()` raises a parsing exception that is not `SignatureVerificationError`, it propagates through the helper. In a typical Flask integration, this results in an HTTP 500 response and an application error log rather than a controlled HTTP 400 response. The handler should not broadly suppress all exceptions, because internal failures should remain observable. It should specifically catch documented malformed-payload exceptions separately from signature failures. ### Attack Path 1. An unauthenticated remote client sends a malformed request body to the public Stripe webhook URL. 2. The endpoint passes the attacker-controlled bytes to `verify_webhook()`. 3. Stripe's event constructor fails while parsing the ma ...[truncated 838 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: stripe-setup
description: Add Stripe payments to any agent-built app. Covers checkout sessions, subscription billing, webhook handling, customer portal, and test-mode validation. Use when you need to accept payments, set up subscriptions, handle billing events, or wire Stripe into a Flask/FastAPI/Express app. No prior Stripe experience needed — follow the steps and you'll have a working payment flow. Assumes Python + Flask on a VPS with a .env file. Adapt patterns for FastAPI, serverless, or other stacks.
---

# Stripe Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/stripe_helpers.py (reported line 182)May include surrounding context.

python
---
name: stripe-setup
description: Add Stripe payments to any agent-built app. Covers checkout sessions, subscription billing, webhook handling, customer portal, and test-mode validation. Use when you need to accept payments, set up subscriptions, handle billing events, or wire Stripe into a Flask/FastAPI/Express app. No prior Stripe experience needed — follow the steps and you'll have a working payment flow. Assumes Python + Flask on a VPS with a .env file. Adapt patterns for FastAPI, serverless, or other stacks.
---

# Stripe Setup

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

bash
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

bash
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

bash
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

bash
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

# Login
stripe login

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description says to use the skill when you need to 'accept payments,' 'set up subscriptions,' or 'wire Stripe into a Flask/FastAPI/Express app,' but it does not define explicit trigger phrases, boundaries, or exclusion conditions. In a manifest-scoped description, this broad natural-language wording can cause unintended invocation for many generic payment-integration requests.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

bash
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

bash
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
# Install Stripe CLI (Linux/VPS)
curl -s https://packages.stripe.dev/api/security/keypair/stripe-cli-gpg/public | gpg --dearmor | sudo tee /usr/share/keyrings/stripe.gpg
echo "deb [signed-by=/usr/share/keyrings/stripe.gpg] https://packages.stripe.dev/stripe-cli-debian-local stable main" | sudo tee /etc/apt/sources.list.d/stripe.list
sudo apt update && sudo apt install stripe

# Login
stripe login

Static analysis

No suspicious patterns detected.