NYC

payment-integration

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a payment integration toolkit for SePay and Polar. It defines APIs/SDKs and workflows for payment gateway integration (checkout, processing), bank transfer automation, VietQR generation, subscription and usage-based billing, checkout session generation (scripts/checkout-helper.js), webhook handling and verification, product/pricing management, and Merchant of Record/tax capabilities. These are specific, direct financial execution capabilities (creating payment transactions, automating bank transfers, managing subscriptions/billing). This meets the criteria for Direct Financial Execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:01 AM