Tribe Payments

Security checks across malware telemetry and agentic risk

Overview

This Stripe skill is coherent, but it gives an agent broad payment-account action and raw API access without clear safety limits for financial changes.

Install only if you trust Membrane and intend to let an agent access your Stripe account. Use the narrowest Stripe permissions available, start with read-only/list actions, require explicit approval before any create, update, delete, refund, payout, transfer, subscription, or pricing change, and review/revoke the Membrane connection when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation actively enables direct action execution and raw proxy API requests against a payment platform without accompanying warnings about destructive, financial, or irreversible operations. In a payments context, that increases the risk of an agent issuing refunds, payouts, chargeback actions, or configuration changes without adequate confirmation or operator awareness.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal