/stripe-refund-auditor
Audit Stripe refunds over a date range to surface anomalies — refund-rate spikes, missing reasons, suspicious duplicates — and emit a markdown report.
When to use
Trigger when the user asks any of:
- "Audit our Stripe refunds for the last 30 days"
- "Check refund anomalies in Stripe"
- "Review refund activity since {date}"
What this skill does
- Read
STRIPE_API_KEYfrom the environment (or.env.localnext to this skill). - Run
scripts/audit.pywith the requested date range. The script paginates through/v1/refundsand emits a JSON record per refund. - Run
scripts/grader.pyover the JSON output to compute a deterministic anomaly score in[0, 1]. - Render a markdown report listing the highest-scoring anomalies with their
id,amount,currency,status, andreason.
Files in this skill
scripts/audit.py— the deterministic refund-pull + anomaly-detection helper.scripts/grader.py— pure-function grader producing a 0..1 numeric score.tests/integration_test.py— pytest integration test (skipped withoutSTRIPE_API_KEY).references/refund-schema.md— Stripe Refund object field reference.evals/evals.json— LLM-judged behavioral evaluation cases..env.example— placeholder template; copy to.env.localand fill in real values.
Preflight
Before invoking, run vskill check stripe-refund-auditor to verify:
- The Stripe MCP server is configured in your Claude config.
STRIPE_API_KEYis resolvable from env or.env.local.- Python
>=3.10is on PATH. pytest --collect-only tests/succeeds.
Step 1 — Pull refunds. Run this immediately:
python3 scripts/audit.py --since "$(date -u -v-30d +%Y-%m-%d)" --until "$(date -u +%Y-%m-%d)" > /tmp/refunds.jsonl
Step 2 — Score anomalies. Run this immediately:
python3 scripts/grader.py /tmp/refunds.jsonl > /tmp/refund-scores.json
Step 3 — Render the report. Run this immediately:
python3 -c "import json,sys; data=json.load(open('/tmp/refund-scores.json')); print(json.dumps({'top_anomalies': data['anomalies'][:10], 'score': data['overall_score']}, indent=2))"
The skill's caller is expected to take the JSON from Step 3 and turn it into
prose. See references/refund-schema.md for the underlying field semantics.
Failure modes
STRIPE_API_KEYmissing →audit.pyexits with code 2 and prints a diagnostic line. Runvskill check stripe-refund-auditorto see which env source is searched.- Empty result set →
grader.pyreturns{"overall_score": 0.0, "anomalies": []}. - Network failure →
audit.pyexits non-zero and the message includes the underlying HTTP status. Re-run after fixing connectivity.