ask-cli

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The ask-cli skill exposes App StoreKit commands for managing in-app purchases, subscriptions, and transactions. It includes explicit transaction execution commands such as "ask transactions refund --app APP_ID --transaction-id TX_ID --reason ...", which perform financial operations (issuing refunds). Because it provides a specific API/command to initiate money-moving actions, it meets the criteria for Direct Financial Execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 03:37 PM