axiom-storekit-ref
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a focused StoreKit 2 in-app purchase reference and includes explicit APIs and examples that perform monetary transactions and server-side purchase management. It documents product.purchase(...) calls (client-side purchase execution), transaction finishing and verification, App Store Server API endpoints (PATCH /inApps/v1/transactions..., PUT /inApps/v2/transactions/consumption/..., refund notifications), and server signature creation for promotional offers. These are specific, purpose-built interfaces for initiating and managing real payments/subscriptions (including refunds and consumption/proration), not generic browser or HTTP tooling. Therefore it grants direct financial execution capability.
Audit Metadata