customer-support-integration
Warn
Audited by Snyk on Mar 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly documents and enables transactional actions from the helpdesk such as "Refund, cancel, or duplicate an order directly from the ticket sidebar", applying discounts, creating draft orders, and logging "refunds, order changes, and status updates initiated from within the helpdesk." Those are non-generic, write actions that change financial state (issue refunds / modify orders) rather than mere browsing or ticket updates. Even though it doesn't name Stripe/PayPal by API, the integration’s purpose includes executing refunds/financial order actions from the support interface, which constitutes direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata