proximity-reader

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly built to implement Tap to Pay and contactless payment acceptance on iPhone. It names payment-specific classes (PaymentCardReader, PaymentCardReaderSession), shows creating PaymentCardTransactionRequest with amount/currency, directs sending paymentCardData or store-and-forward batch.data to a PSP, and references integration with Level 3 certified PSPs (Stripe, Adyen, Square, Windcave) and reader tokens/JWTs. These are specific payment gateway/transaction operations (not generic browser or HTTP tooling) and therefore constitute direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:44 PM