CtrlK
BlogDocsLog inGet started
Tessl Logo

stripe-apps

Use when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g. "add a panel to the customer page", "customize my Stripe Dashboard", "react to Stripe events from my app", "connect my service to Stripe without sharing API keys"). Covers the full app development workflow (scaffold, preview, upload, versioning), UI extension architecture (sandboxed iframe, Stripe UI toolkit, viewports), extension types (UI extensions, backend-only, extension interfaces, embedded apps), authentication (platform keys, OAuth, restricted API keys), stripe-app.yaml manifest setup (permissions, viewports, CSP), webhook configuration for apps, Secret Store API, `fetchStripeSignature` auth, and marketplace publishing, plus submitting one agentic feedback report after a build. Use when the user mentions Stripe Apps, UI extensions, @stripe/ui-extension-sdk, @stripe/extensibility-sdk, script extensions, stripe-app.yaml, Dashboard extensions, or customizing the Stripe Dashboard.

76

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is stripe-apps in stripe/ai

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered instruction skill: hard rules, blocked-pattern table, ordered protocol with a file-verification checkpoint, and a genuinely useful troubleshooting table, all delegating code patterns to canonical docs and one-level-deep references. The two real defects are the broken reference-link hrefs and recurring restatements of the same mandates that cost tokens without adding guidance.

Suggestions

Fix the reference link hrefs to relative paths — they currently point to https://docs.stripe.com/references/<file> (e.g. change [references/discovery.md](https://docs.stripe.com/references/discovery.md) to [references/discovery.md](references/discovery.md)) so navigation resolves to the local bundle files.

State the WebFetch-the-canonical-docs mandate once (e.g. in Hard Rule 4) and reference it elsewhere, instead of repeating the full instruction in the 'Source of truth' section, Step 3, and the reference table.

Compress the 'Your role' persona prose ('You are a PROJECT BUILDER and INSTRUCTOR... You are also a patient guide') into the two operative directives (write files to disk; explain in plain language), cutting redundant tokens from the always-loaded body.

DimensionReasoningScore

Conciseness

The body is dense and directive (tables for hard rules, blocked patterns, architecture→file mapping, troubleshooting) with no explanation of concepts Claude already knows, but it repeats the docs-first mandate four times ("Source of truth" section, Hard Rule 4, Step 3 intro, the reference table) and carries persona prose ("You are a PROJECT BUILDER and INSTRUCTOR... You are also a patient guide") that could be trimmed.

4 / 5

Actionability

Commands are copy-paste ready (`stripe generate app <name>`, `pnpm build`, `stripe apps upload`), filenames are exact (`ui/src/views/App.tsx`, `server.js`), the discovery questions and user-facing summary template are given verbatim, and the architecture table maps each answer set to the exact files to modify or create. Code samples are deliberately delegated to WebFetch'd canonical docs plus reference files, which is an explicit, justified design rather than a gap.

5 / 5

Workflow Clarity

The Protocol is a strictly ordered 5-step sequence (discover → confirm → scaffold → build → deliver) with an explicit validation checkpoint (Step 5: `ls` the written files, re-Write any missing one), a required user confirmation gate before scaffolding, and a troubleshooting table mapping upload errors to fixes — feedback loops and checkpoints are all present.

5 / 5

Progressive Disclosure

The overview stays lean and the 13 reference files are all real, one level deep, and indexed in a "read when" table — but the markdown link hrefs are wrong: every link points to `https://docs.stripe.com/references/<file>` instead of the relative local path (e.g. `[references/discovery.md](https://docs.stripe.com/references/discovery.md)`), so clicked navigation breaks and only the backtick plain-text paths resolve.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A model description: explicit double 'Use when' triggers with both natural phrasings and exact SDK/filename tokens, paired with a comprehensive, concrete capability inventory. It is on the long side (~160 words) but every clause is a trigger or a capability, so the length is dense rather than padded.

DimensionReasoningScore

Specificity

The description enumerates many concrete actions and artifacts — "building, modifying, or reviewing a Stripe App", "scaffold, preview, upload, versioning", "stripe-app.yaml manifest setup (permissions, viewports, CSP)", "Secret Store API, `fetchStripeSignature` auth, and marketplace publishing" — covering the whole app lifecycle comprehensively rather than in generic terms.

5 / 5

Completeness

It opens with an explicit "Use when building, modifying, or reviewing a Stripe App" trigger, closes with a second concrete "Use when the user mentions..." trigger list, and the 'what' is a detailed coverage statement — both halves are explicit and concrete, matching the top anchor.

5 / 5

Trigger Term Quality

It captures natural user phrasings ("add a panel to the customer page", "customize my Stripe Dashboard", "react to Stripe events from my app", "connect my service to Stripe without sharing API keys") plus the exact technical tokens a user would drop: @stripe/ui-extension-sdk, @stripe/extensibility-sdk, script extensions, stripe-app.yaml, Dashboard extensions.

5 / 5

Distinctiveness Conflict Risk

The niche is unambiguous (Stripe Apps, not general Stripe API work) and the triggers are dominated by app-specific terms (UI extensions, stripe-app.yaml, Dashboard extensions, Apps CLI); only "connect my service to Stripe without sharing API keys" could plausibly bleed into a general Stripe-integration skill, which is minimal overlap.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
stripe/ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.