marketplace-building
Warn
Audited by Snyk on Mar 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to handle payments and move money. It prescribes and demonstrates integration with a payment gateway (Stripe Connect) for onboarding sellers, KYC, holding funds, and automated payouts. The prompt includes concrete API calls and code examples that create Stripe accounts, generate onboarding links, handle webhooks, and—critically—initiate transfers (stripe.transfers.create) to connected seller accounts. These are specific financial execution operations (payment gateway integration and fund transfers), not generic tooling.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata