spec-builder

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The spec-builder explicitly references payment gateway integrations and payment-related APIs. The prompt's templates and examples include "Subscription billing", "Checkout flow", "Payment with saved cards", "Direct deposit payouts", and specifically names Stripe Connect as part of the recommended technology stack. These are concrete, named financial integrations (payment gateway / payout API) rather than generic capabilities, so the skill includes explicit financial execution tooling.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:06 AM