payment-integration
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a payment gateway integration for HitPay. It includes concrete APIs and code to create payment requests (POST to https://api.hit-pay.com/v1/payment-requests), generate QR-based payment payloads, redirect users to hosted checkout URLs, handle webhooks for payment completion (including signature verification), and requires API keys/salts. These are specific, purpose-built actions to initiate and confirm financial transactions (move money), not generic tooling.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata