Security audit
Drivethru Stripe
Security checks across malware telemetry and agentic risk
Overview
This is a disclosed Stripe helper for catalog lookup and checkout-link creation, with the main risk being live Stripe credentials can create real payment sessions.
Install only if you want an agent to access your Stripe catalog and create checkout links. Prefer Stripe test mode first, use restricted keys where possible, and require explicit confirmation of live mode, customer, items, and total amount before generating a real payment or subscription session.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
