stripe
Warn
Audited by Snyk on Feb 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly and specifically designed for payment processing via Stripe. It references Stripe SDKs, secret/publishable API keys, Checkout Sessions, Payment Intents, refunds, payouts, subscriptions, Stripe Connect (marketplace splits), webhooks for payment events, and server actions/templates for checkout, subscription CRUD, and portal sessions. Those are direct payment gateway operations capable of moving money (charging cards, issuing refunds, creating payouts), so this is Direct Financial Execution.
Audit Metadata