Agent Toolkit

stripe/agent-toolkit0🔧 5 tools

D4.4SpiderScore (registry)

One-stop shop for building AI-powered products and businesses with Stripe.

Decision
Allow with Risk
Confidence
90%

Agent Toolkit has risks — usable with isolation (4.44/10, 1 critical, 0 high).

Recommended Actions

  • high
    Run In Container
    1 critical vulnerabilities require isolation
  • high
    Limit Permissions
    Restrict tool access to minimum required scope

Do Not

  • running in production without container isolation
Risk Flags (1)
  • critical
    sql_injection
    SQL injection — .execute() called with f-string (user input may reach query)
How This Was Decided
  • negativew=0.5Overall quality score = 4.44/10 (grade D)
  • negativew=0.81 critical security issue(s) detected
  • negativew=0.3Tool description clarity score = 2.2/10
Source: SpiderRating automated security scanUpdated: 2026-03-13Protocol: v1.1

Description Quality

Composite: 2.2 / 10

3-Layer Breakdown

Description (38%)
2.2
Security (34%)
8.9
Metadata (28%)
2.0

Description Dimensions

Intent Clarity
3.2
Permission Scope
0.0
Side Effects
2.0
Capability Disclosure
4.0
Operational Boundaries
2.5

Category Ranking: Cloud Platforms

#46 of 49 · Top 94%
Overall#464.4 (avg 5.8)
Security#28.9 (avg 7.6)
Description#462.2 (avg 5.5)
Metadata#492.0 (avg 4.3)

Why #46 in Cloud Platforms?

Top 94% of 49 tools
Security#2
8.9avg 7.6
Description#46
2.2avg 5.5
Metadata#49
2.0avg 4.3

How to reach #45? Need +0.5 overall to pass Lawsuit (5.0). Biggest opportunity: Description is 3.3 below category average.

Top action: Add action verbs to 4 tool descriptions (e.g. 'Creates...', 'Deletes...') (+0.2)

Security Analysis

8.9
Score
1
Critical
0
High
0
Medium
0
Low

Findings Redacted

Detailed security findings are hidden during the 90-day responsible disclosure window. Maintainers have been notified.

1 CRITICAL

Metadata Health

Provenance (40%)
5.0
Maintenance (35%)
0.0
Popularity (25%)
0.0

Badge

Add this badge to your README:

[![SpiderRating](https://spiderrating.com/badge/stripe__agent-toolkit.svg)](https://spiderrating.com/servers/stripe/agent-toolkit)