fynd-theme

Warn

Audited by Snyk on Mar 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly references and relies on platform payment and order APIs: "Payments | FPI payment actions + platform PG integration", fpi.cart.addItems(), fpi.order.* actions, checkout and refunds/returns handled via FPI order management, and guidance to use FPI payment actions rather than custom implementations. These are specific platform APIs for moving money / placing orders (payment gateway integration and order placement), not generic tooling, so it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 07:02 PM