cloud-cost-management
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly about cloud cost management and includes concrete commands and IaC examples that create billing-related resources and commitments. Examples that constitute direct financial execution include:
- Terraform aws_savingsplans_savings_plan with commitment and payment_option = "ALL_UPFRONT" (purchases a savings plan / commits/spends money).
- aws_ec2_capacity_reservation / reserved instances and gcloud compute commitments create (creates paid commitments/reservations).
- CLI/IaC commands to create budgets and billing alerts (aws budgets create-budget, gcloud billing budgets create, az consumption budget create) which modify billing configuration.
These are not generic "view only" examples — they show creating/updating resources that result in financial commitments or change billing behavior. Therefore the skill contains specific APIs/actions that can move or commit money.
Audit Metadata