CtrlK
BlogDocsLog inGet started
Tessl Logo

stripe-best-practices

Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (Stripe Tax, automatic_tax, product tax codes), Treasury financial accounts, integration options (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, API key permissions, webhooks, OAuth). Use when planning, building, modifying, testing, or reviewing any Stripe integration, including choosing a development environment, accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, collecting sales tax, VAT, or GST, creating connected accounts, or implementing secure key handling.

84

1.78x
Quality

87%

Does it follow best practices?

Impact

100%

1.78x

Average score across 2 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

The canonical home for this skill is stripe-best-practices in stripe/ai

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, highly actionable routing layer: a decision table, exact CLI commands and parameter names, and sharply worded critical rules, all correctly deferring detail to six real reference files. Main deductions are version-pin staleness outside a deprecated section and reference links pointing at external URLs instead of the bundled relative paths.

Suggestions

Move the pinned API version (2026-08-26.dahlia) and the SDK version table into a clearly labeled 'Current versions' or 'Deprecated/old patterns' style section so staleness is self-evident and doesn't read as evergreen guidance.

Change reference links to relative paths (e.g. [references/payments.md](references/payments.md)) so they resolve to the bundled files rather than docs.stripe.com URLs.

Add one minimal copy-paste example for the most common case (e.g. a Checkout Session create with integration_identifier and the 8-random-letter suffix) to close the actionability gap without delegating everything to references.

DimensionReasoningScore

Conciseness

The body is efficient — a routing table, imperative critical rules, and exact commands with no explanation of concepts Claude already knows — but time-sensitive version pins ("Latest Stripe API version: 2026-08-26.dahlia", the SDK version table, "On API version 2026-03-25.dahlia or later") are not placed in a deprecated/old-patterns section, which the guidelines penalize. Fits the 4 anchor (efficient, minor trimmable elements) better than 3 (no noticeable padding or unnecessary explanation).

4 / 5

Actionability

Highly concrete guidance throughout: exact commands ("stripe sandbox create", "stripe whoami --format json"), exact parameters ("automatic_tax: { enabled: true }", "payment_method_types: ['card_present']", "integration_identifier"), and a decision routing table. It falls short of the 5 anchor only because no complete copy-paste code example appears in the body itself — implementation detail is delegated to reference files, and the "pass the parameter integration_identifier… suffix of 8 random letters" rule lacks an example value.

4 / 5

Workflow Clarity

The decision workflow is clear and sequenced: route via the "Integration routing" table, "Read the relevant reference file before answering any integration question or writing code", then apply the "Critical rules" — with one explicit confirmation gate ("confirm the user has an active registration" before enabling automatic_tax). It is not 5 because there are no explicit verification/error-recovery checkpoints, and not 3 because the sequence and key checkpoints are present and coherent.

4 / 5

Progressive Disclosure

The body is a genuine overview with well-signaled, one-level-deep references, and every referenced bundle file (references/payments.md, connect.md, billing.md, tax.md, treasury.md, security.md) exists on disk. Minor gap: reference links point to external URLs (https://docs.stripe.com/references/payments.md) rather than relative paths to the bundled files, slightly muddying navigation; this matches the 4 anchor's "references mostly clear; minor organization gaps" rather than the 5 anchor's easy navigation.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: third-person voice, comprehensive concrete capabilities with named Stripe APIs, and an explicit "Use when" clause covering natural user phrasings and synonyms. It is dense but every clause is informational rather than padded, so verbosity is not penalized.

DimensionReasoningScore

Specificity

Lists multiple specific concrete capabilities across every major Stripe domain with named APIs and parameters — "API selection (Checkout Sessions vs PaymentIntents)", "Connect platform setup (Accounts v2, controller properties)", "tax and registrations (Stripe Tax, automatic_tax, product tax codes)", "security best practices (API key management, API key permissions, webhooks, OAuth)" — which matches the comprehensive-coverage anchor rather than the minor-gaps anchor at 4.

5 / 5

Completeness

Explicitly answers both: what ("Guides Stripe integration decisions across development and test environment planning… migrating from deprecated Stripe APIs, and security best practices") and when ("Use when planning, building, modifying, testing, or reviewing any Stripe integration"), with concrete trigger phrases exactly as the top anchor describes.

5 / 5

Trigger Term Quality

The "Use when" clause enumerates natural user phrasings with synonyms — "planning, building, modifying, testing, or reviewing any Stripe integration", "accepting payments", "building marketplaces", "setting up subscriptions", "collecting sales tax, VAT, or GST", "creating connected accounts", "implementing secure key handling" — comprehensive natural-term coverage, not the "a few natural terms missing" level of 4.

5 / 5

Distinctiveness Conflict Risk

The entire scope is Stripe-specific (sandboxes, Checkout Sessions, PaymentIntents, Connect, Stripe Tax, Treasury, RAK-style key management) with distinct trigger vocabulary, giving it a clear niche with minimal conflict risk; not the 4 anchor, which implies overlap with closely related skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
stripe/ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.