Security audit
pontx-stripe-identity
Security checks for vulnerabilities and agentic risk
Overview
This skill provides safety guidance for integrating Stripe Identity through Pontx and does not contain hidden execution, persistence, or exfiltration behavior.
Install only if you intend to build or operate Stripe Identity flows. Follow its guidance carefully: keep Stripe credentials server-side, avoid logging PII or raw events, verify webhooks, use dry-run previews, and require explicit approval before cancellation or redaction because those actions can be irreversible.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
