project-bootstrapper

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The meta-skill explicitly includes a conditional domain "payment-integration — billing, subscriptions, webhooks, PCI" in its skill catalog and generation layers. That is a project-specific payment domain (billing/subscriptions/webhooks/PCI) intended to produce concrete, project-specific guidance and code for integrating payment systems — i.e., handling payment flows and transactions. Under the core rule, this is a domain-specific financial operation (not a generic tool), so it meets the criteria for Direct Financial Execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 09:40 AM