ai-billing

Warn

Audited by Snyk on Apr 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for billing and balance management: tracked() reports token usage to the Commet billing service which "calculates cost from the AI model catalog and deducts from the customer's balance." The doc repeatedly states "balance deduction is real-time", "deduct from balance", "record ledger entry", and exposes error codes like 402 (insufficient balance). This is a specific financial/billing integration (Commet API) whose primary function is to charge/deduct customer balances — i.e., execute financial transactions — not a generic tool. Therefore it constitutes direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 05:04 PM
Issues
1