Stripe Full Read Access

Security checks across malware telemetry and agentic risk

Overview

This Stripe skill is framed as read-only but appears to allow account-changing Stripe actions when asked.

Review this carefully before installing. Use a narrowly scoped read-only Stripe restricted key if possible, do not provide a full secret key unless you intend to allow financial changes, and require explicit confirmation before any refund, payout, transfer, subscription, customer, or account mutation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill is presented as a read-only Stripe access skill, but its safety guidance explicitly allows write operations whenever a user asks. Because it uses a Stripe secret or broadly scoped restricted key and documents direct API authentication, this weakens the intended safety boundary and can enable destructive or financially sensitive actions such as refunds, payouts, transfers, or account changes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal