NYC

axiom-storekit-ref

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a focused StoreKit 2 in-app purchase reference and includes explicit APIs and examples that perform monetary transactions and server-side purchase management. It documents product.purchase(...) calls (client-side purchase execution), transaction finishing and verification, App Store Server API endpoints (PATCH /inApps/v1/transactions..., PUT /inApps/v2/transactions/consumption/..., refund notifications), and server signature creation for promotional offers. These are specific, purpose-built interfaces for initiating and managing real payments/subscriptions (including refunds and consumption/proration), not generic browser or HTTP tooling. Therefore it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:35 PM