Is felipeoff/stripe-cli-skill safe?
Yes. felipeoff/stripe-cli-skill is safe to install. Oathe's behavioral security audit gave the stripe-cli-skill skill by felipeoff a trust score of 99/100 with 2 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/felipeoff/stripe-cli-skill
Is felipeoff/stripe-cli-skill safe to install?
This is a well-designed Stripe CLI wrapper skill that follows security best practices with sandbox-first operations, localhost-only webhook forwarding, and clear security guardrails. The included shell scripts are transparent and safe, serving legitimate development purposes.
What security issues were found in felipeoff/stripe-cli-skill?
Category Scores
Findings (2)
LOW Sensitive file system access during installation -5 ▶
During skill installation, sensitive files including .env, SSH keys, and AWS credentials were accessed by system processes. However, files were not modified and canary integrity was maintained, suggesting normal SSH/system behavior rather than malicious access.
INFO API interaction capabilities -5 ▶
Skill enables interaction with Stripe APIs and webhook forwarding, which carries inherent risks if misused. However, skill implements security guardrails including localhost-only forwarding restrictions and sandbox-first approach.
Should I install felipeoff/stripe-cli-skill?
Oathe's verdict for felipeoff/stripe-cli-skill is SAFE with a trust score of 99/100. Recommendation: Install.