stripe-directory-b6a55e — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited stripe-directory-b6a55e (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Turn a vague market need into a short, relevant shortlist with stripe directory search. Use this even when the user never says “Stripe Directory” — any request to find vendors, tools, partners, or providers for a vertical, workflow, pain point, or job-to-be-done.
Most requests are discovery — find and compare services. That is the core job below. Some services are also MPP-supported (MPP = Machine Payment Protocol), meaning you (the agent) can pay their HTTP 402 (Payment Required) endpoint and consume them directly. When the user actually wants to use or buy a service, present those results and offer to purchase — see “Purchasing” at the end.
stripe directory search "<query>" --format jsonelectrician software, electrical contractor) → workflow (field service management, dispatch invoicing estimates) → pain point (job scheduling, quote automation) → adjacent (home services automation, contractor crm).b2b saas billing, developer tools) → workflow (subscription management, usage-based metering) → pain point (failed payment recovery, revenue recognition) → adjacent (analytics dashboards, customer onboarding).--countries-supported=US, --has-stripe-app=true, --link-supported=true, --stripe-projects-supported=true.--mpp-supported in at least one search to find results you can pay for programmatically.--limit and try the next --page before concluding it’s empty.display_name, description, url, username as evidence.projects.catalog_command / projects.install_command (stripe projects catalog <provider>, stripe projects add <provider>).mpp.slug / mpp.url.Always report the exact queries (and filters) you ran so the user can keep iterating.
MPP-supported results are payable directly. Don’t drive to purchase unprompted. When the user wants to buy, present the full menu of payment methods and ask which they’d like to use before doing anything:
"Which payment method would you like to use?
>
- Link CLI — Stripe-native, test mode available (recommended)
Once the user picks, silently run which <tool> 2>/dev/null to check if it’s installed. If not installed, offer to install it (for example, npm i -g @stripe/link-cli for Link CLI) and wait for confirmation before proceeding.
Always show the price and get explicit user approval before any money moves; prefer a no-charge test path first.
Short version:
mpp.slug / mpp.url. mpp.url is often the mpp.dev landing form (https://mpp.dev/services#<slug>) — resolve the raw endpoint on mpp.dev if so. Read the HTTP 402 challenge to confirm the amount: curl -s -D - -o /dev/null <endpoint_url> (look for WWW-Authenticate).npm i -g @stripe/link-cli): auth login → mpp decode --challenge "<value>" (get network_id) → spend-request create --credential-type shared_payment_token --network-id <id> --amount <cents ≤50000> --context "<100+ chars>" --request-approval (blocks for approval) → mpp pay <endpoint_url> --spend-request-id <approved_id>.tempo wallet login / services / request.@privy-io/agent-wallet-cli.Never invent results or skip the price/approval gate.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.