Skip to main content

stripe-security-audit

Audits Stripe security posture -- API key hygiene, restricted keys, secret leakage, PCI scope, and webhook signature verification. Use when the user mentions "Stripe security", "key management", "restricted keys", "secret leak", "PCI", or "is our Stripe setup secure".

跳到安装

来源信息

仓库
appeeky/stripe-skills
最近来源活动
2026年7月19日 10:10
检测到的 SKILL.md 语言
英语
星标
5
分支
1

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
stripe-security-audit
description
Audits Stripe security posture -- API key hygiene, restricted keys, secret leakage, PCI scope, and webhook signature verification. Use when the user mentions "Stripe security", "key management", "restricted keys", "secret leak", "PCI", or "is our Stripe setup secure".
metadata
{"version":"1.0.0"}
# Stripe Security Audit Combines codebase scan + account settings review. ## Codebase scan Grep for leaked secrets: `sk_live`, `sk_test`, `rk_live`, `whsec_`, hardcoded keys outside env. ## Checklist | Area | Check | |------|-------| | Secret keys | Only in env/secrets vault, never client or repo | | Publishable key | `pk_` only on client (safe) | | Restricted keys | Used for scoped/agent access, least privilege | | Webhook | `whsec_` verified, not skipped | | PCI scope | Using Checkout/Elements (SAQ-A), not raw card handling | | Logging | No full card / secret / client_secret in logs | | Key rotation | Old keys revoked in Dashboard | ## Output Template ``` Security Audit Critical: - [leaked/hardcoded key at file:line] Harden: - [use restricted key for X] OK: - [Checkout keeps PCI scope minimal] Immediate: [rotate/remove any exposed key] ``` If a live secret key is found in the repo, advise **rotating it immediately** in the Dashboard.
在 GitHub 查看