Back to skill

Security audit

Drivethru Stripe

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Stripe skill for catalog lookup and hosted checkout links, with real-money risk only when a live Stripe key is intentionally configured.

Install only in an environment where the agent may use a Stripe secret key. Prefer a test-mode or restricted Stripe key, review the checkout amount and mode before generating live links, treat returned checkout URLs as sensitive, and pin or lock the Stripe SDK version if you need reproducible installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unbounded Stripe SDK Dependency Exposes the Skill to Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15-17, scripts/list_products.py:19-25, and scripts/create_checkout_session.py:19-25
Vulnerability Type: Unbounded third-party dependency
Risk Level: Medium

Vulnerable Code

SKILL.md:15-17:

yaml
install:
  uv:
    - stripe>=10.0.0

scripts/list_products.py:19-25:

python
{
    "error": {
        "type": "dependency_error",
        "message": "The 'stripe' Python package is not installed. Install it with: pip install 'stripe>=10.0.0'",
    }
}

scripts/create_checkout_session.py:19-25:

python
{
    "error": {
        "type": "dependency_error",
        "message": "The 'stripe' Python package is not installed. Install it with: pip install 'stripe>=10.0.0'",
    }
}

Technical Analysis

The installation declaration and runtime instructions specify only a minimum Stripe SDK version. They do not impose an upper bound, pin an exact reviewed version, provide package integrity hashes, or include a committed dependency lockfile.

Consequently, a future installation can resolve to a package release that was not represented in this audit. Python package installation may execute package build or installation logic, while importing the installed package executes its module initialization code. The Skill subsequently gives that dependency access to the process containing STRIPE_SECRET_KEY.

The Stripe SDK itself is a legitimate and necessary dependency for the declared functionality. The vulnerability is therefore not the use of Stripe or the required Stripe API traffic, but the absence of reproducible and integrity-verified dependency resolution.

Attack Path

  1. An attacker compromises the dependency distribution channel, a maintainer account, or a future package release accepted by the unbounded constraint.
  2. The Skill is installed or repaired using stripe>=10.0.0.
  3. Dependency ...[truncated 1679 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the Stripe SDK to an exact version that has been reviewed and tested, for example:

    yaml
    install:
      uv:
        - stripe==REVIEWED_VERSION
    
  2. Commit a dependency lockfile generated by the selected package manager and require hash verification during installation.

  3. Update the installation guidance in both Python scripts so it does not recommend an open-ended version range.

  4. Retrieve packages only from an explicitly configured trusted package index, with fallback indexes disabled where practical.

  5. Introduce a controlled dependency-update process that includes security review, automated tests, and deliberate lockfile regeneration.

  6. Use a Stripe restricted API key granting only the Product, Price, and Checkout Session permissions required by this Skill.

  7. Prefer test-mode credentials by default and expose live credentials only for explicitly confirmed production operations.

  8. Run the Skill in a sandbox with restricted filesystem and outbound-network access so a compromised dependency cannot freely access unrelated host data or endpoints.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The implemented code accurately supports the Checkout Session creation portion of the description, including payment, subscription, and setup modes, and returns a hosted checkout URL. However, the description also claims the skill can 'look up products in the Stripe catalog' and be used to 'browse what's for sale.' No code accesses Stripe products, prices, or catalog-listing endpoints; it only accepts provided line items and creates a checkout session. That is a material declared capability not represented by the supplied code chunk, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code implements product catalog lookup only: it reads a Stripe secret key, accepts optional filters, retrieves/searches/lists Stripe products, fetches associated prices, and outputs product data. There is no call to any Stripe Checkout Session creation endpoint, no payment/session initialization, and no URL generation. Thus the description overstates the skill's capabilities in a material way.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill requires access to a highly sensitive environment secret (STRIPE_SECRET_KEY) but does not declare an explicit tool/permission scope such as allowed tools or secret access boundaries. In an agent ecosystem, missing scope declarations can lead to overbroad secret exposure or invocation in contexts where users and orchestrators do not clearly understand that payment-capable credentials are being used.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- Test mode key: `sk_test_...` (use during development; charges are not real)
- Live mode key: `sk_live_...` (real money — only after explicit user confirmation)

If `STRIPE_SECRET_KEY` is missing, stop and tell the user to set it. Do not prompt the user to paste the key into chat — secrets must come from the environment.

Optional environment variables:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says the skill is for browsing products, collecting a one-time payment, or starting a subscription via a Stripe-hosted page. The code explicitly allows setup mode, which creates a Checkout Session for saving a payment method rather than charging a customer or starting a subscription, so the implemented behavior is broader than described.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.