paymeuz-clickuz-master

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly and specifically designed to integrate two payment gateways (Payme.uz and Click.uz) into a NestJS application. It includes payment link generation, gateway-specific webhook handling, signature verification, JSON-RPC methods for creating/performing/canceling transactions, refund logic, and merchant authentication. These are direct payment gateway integration primitives (i.e., "send/confirm transactions" and manage transaction state), not generic tooling. Under the core rule, this is Direct Financial Execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 10:44 AM