aws-cost-finops

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a FinOps/cost-optimization tool that not only analyzes costs but instructs and automates actions that directly change billing and commit spend. It explicitly describes purchasing commitments (Reserved Instances / Savings Plans) and states "Purchase through AWS Console or CLI", includes CLI/SDK commands (e.g., aws ec2 request-spot-fleet) and scripts that run with AWS credentials (boto3). Those are specific, actionable instructions to create paid commitments and request resources that affect charges — i.e., perform financial transactions/commitments in AWS. Therefore it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:45 PM