スキル stripe-projects
📦

stripe-projects

コンテンツリビジョン r1 高リスク ⚙️ 外部コマンド🌐 ネットワークアクセス

Stripe Projects でサービスをプロビジョニング

開発者は多くの場合、コーディングワークフローを離れることなく、データベース、認証、ホスティング、API認証情報を必要とします。このスキルは、Claude、Codex、Claude Code に Stripe Projects CLI のプロビジョニング手順を案内します。

対応: Claude Codex Code(CC)
⚠️ 38 不十分

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "stripe-projects" from https://skillstore.io/skills/stripe-stripe-projects.md and its manifest at https://skillstore.io/api/skills/stripe-stripe-projects/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「stripe-projects」を使用しています。 プロトタイプ用のデータベースが必要です。

期待される結果:

このスキルはカタログを検索し、利用可能なデータベースプロバイダーを確認し、必要に応じてプロジェクトを初期化して、選択されたサービスを追加します。

「stripe-projects」を使用しています。 すでに接続されているサービスは何ですか?

期待される結果:

このスキルはプロジェクトのステータスを確認し、プロバイダー名、サービスタイプ、ティア、環境変数名のみを報告します。

「stripe-projects」を使用しています。 メールプロバイダー用の APIキーが必要です。

期待される結果:

このスキルはカタログ内のメールプロバイダーを検索し、承認されたプロビジョニングまたは連携フローを開始します。

セキュリティ監査

高リスク

Most Markdown backtick detections are false positives because they mark examples, tables, or fixed CLI commands. Real risks remain around package and plugin installation, project initialization, user-controlled CLI arguments, sensitive environment files, and a handoff to a locally installed skill. No prompt injection attempt was found in SKILL.md.

1
スキャンされたファイル
133
解析済み行数
9
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (2)

高
Environment file access
Only inspect `.projects/` or `.env` directly if the user explicitly asks you to — the CLI is authori
The line permits direct inspection of .projects or .env when the user asks. Those files may contain credentials, so outputs need strict redaction.
高
Unaudited Local Skill Handoff
The skill says project initialization installs stripe-projects-cli under .claude/skills, then tells the agent to invoke that local skill. That follow-on skill is not included in this marketplace report, so later instructions may be unaudited.
The handoff is explicit in SKILL.md and it changes the instruction set used after initialization. I did not inspect the generated local skill because it is not part of the provided static analysis.
機能レビュー項目 (9)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

高
Ruby/shell backtick execution
If `OK`: use the locally-installed `stripe-projects-cli` skill (invoke using the Skill tool with nam
The line tells the agent to invoke a locally installed skill. That skill is outside this audited package and can alter later agent behavior.
中
Ruby/shell backtick execution
- **macOS (Homebrew):** `brew install stripe/stripe-cli/stripe` (or `brew upgrade stripe/stripe-cli/
The skill tells the agent to install or upgrade the Stripe CLI with Homebrew. Package installation changes the host and fetches software from outside the workspace.
中
Ruby/shell backtick execution
```bash
The skill tells the agent to install the Stripe Projects plugin. Installing CLI plugins changes local tooling and executes third-party distributed code.
中
Ruby/shell backtick execution
```bash
The command accepts a user-provided query placeholder. If an agent constructs it without quoting or validation, shell metacharacters in the query could be interpreted.
中
Ruby/shell backtick execution
```bash
The skill instructs stripe projects init --yes, which mutates local project state and may trigger authentication. It should require explicit user consent.
中
Ruby/shell backtick execution
```
The surrounding block documents that initialization may open a browser and install a local skill. Those side effects are real even though the matched token is a fence.
中
Ruby/shell backtick execution
**Important:** `stripe projects init` installs the `stripe-projects-cli` skill locally at `.claude/s
The line states that initialization installs a local skill under .claude/skills. Adding executable agent instructions to the workspace is a security-relevant side effect.
中
Ruby/shell backtick execution
If `MISSING`: re-run `stripe projects init --yes` — the skill is bundled with the Projects plugin an
The line tells the agent to rerun project initialization when the local skill is missing. That repeats a state-changing command and skill installation path.
中
Ruby/shell backtick execution
| `PROVIDER_NOT_LINKED` | Provider requires OAuth linking | Run `stripe projects link <provider>` —
The recovery command can start provider OAuth linking and may open a browser. It links external accounts and should require explicit user confirmation.
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/stripe-stripe-projects/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/stripe-stripe-projects/security.svg)](https://skillstore.io/skills/stripe-stripe-projects?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/stripe-stripe-projects?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/stripe-stripe-projects/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/stripe-stripe-projects.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

stripe. (2026). stripe-projects security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/stripe-stripe-projects/audits/5

BibTeX形式の引用

@techreport{stripe-stripe-stripe-projects-2026, author = {stripe}, title = {stripe-projects security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/stripe-stripe-projects/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "stripe-projects security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "stripe" date-released: "2026-07-07" url: "https://skillstore.io/skills/stripe-stripe-projects/audits/5" identifiers: - type: other value: "skillstore:stripe-stripe-projects:audit:5" description: "Skillstore immutable audit report identifier"

Skillstore スコア

このスコアの理由 証拠の信頼度: 中
55
アーキテクチャ
85
保守性
85
コンテンツ
67
コミュニティ
83
仕様準拠

作成できるもの

アプリのインフラを追加する

Stripe Projects カタログからデータベース、キャッシュ、認証プロバイダー、またはホスティングサービスをプロビジョニングします。

プロジェクト設定を確認する

シークレット値を公開せずに、初期化済みプロジェクトのステータスを確認し、環境変数名を一覧表示します。

AIサービススタックを構築する

LLMアクセス、ベクトルストレージ、オブジェクトストレージ、検索、メール送信用のプロバイダーを見つけます。

これらのプロンプトを試す

利用可能なサービスを閲覧する
Stripe Projects カタログを表示し、このアプリ向けのデータベースオプションを提案してください。
必要なインフラを追加する
Stripe Projects を使用して、このプロジェクトに Postgres と Redis を追加してください。環境変数名のみ表示してください。
AIスタックをプロビジョニングする
LLM、ベクトルデータベース、オブジェクトストレージ、メール送信用のプロバイダーを見つけてください。プロビジョニング前に利用可能なオプションを比較してください。
プロジェクト設定を復旧する
Stripe Projects のステータスを確認し、ローカルの CLI スキルが利用可能か確認して、プロバイダー連携エラーを診断してください。

ベストプラクティス

  • エージェントに続行を依頼する前に、ブラウザ認証を完了してください。
  • シークレット値ではなく、環境変数名を要求してください。
  • 有料サービスをプロビジョニングする前に、プロバイダーの選択肢とティアを確認してください。

回避

  • エージェントに .env のシークレット値を表示するよう依頼しないでください。
  • コスト、リージョン、ティアを確認せずにサービスをプロビジョニングしないでください。
  • .projects や生成された環境ファイルを手作業で編集しないでください。

よくある質問

このスキルはクラウドリソースを作成しますか?
はい。サポートされているサードパーティサービスをプロビジョニングまたは接続する Stripe Projects CLI フローを実行できます。
Stripe CLI なしで動作しますか?
いいえ。プロビジョニングを続行するには、Stripe CLI と Projects plugin が必要です。
API認証情報を取得できますか?
環境変数の設定を支援できますが、応答には名前のみを表示すべきです。シークレット値は伏せたままにしてください。
サービスカタログを閲覧できますか?
はい。プロバイダーを選択する前に、Stripe Projects カタログを検索または閲覧できます。
認証が必要な場合はどうなりますか?
CLI がブラウザを開く場合があります。エージェントが続行する前に、ユーザーがサインインを完了する必要があります。
Claude、Codex、Claude Code と互換性がありますか?
はい。レポートでは、Claude、Codex、Claude Code がサポート対象ツールとして記載されています。

開発者情報

作成者

stripe

ライセンス

MIT

Skillstore リビジョン

r1

バージョンに関する注意

作者はバージョンを宣言していません。

参照

f93e9bb0daca99badb6a7e574b97737155d57cb3

メンテナンスの新しさ

2026/7/22

利用状況

4 ダウンロード · 3 閲覧

ファイル構成

📄 SKILL.md

stripe のその他のスキル

すべて表示
すべて表示