ai-billing
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed for billing and balance management: tracked() reports token usage to the Commet billing service which "calculates cost from the AI model catalog and deducts from the customer's balance." The doc repeatedly states "balance deduction is real-time", "deduct from balance", "record ledger entry", and exposes error codes like 402 (insufficient balance). This is a specific financial/billing integration (Commet API) whose primary function is to charge/deduct customer balances — i.e., execute financial transactions — not a generic tool. Therefore it constitutes direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata