aba-payway
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a payment integration for the ABA PayWay gateway. It defines merchant/API credentials (ABA_PAYWAY_API_KEY, ABA_PAYWAY_MERCHANT_ID, ABA_PAYWAY_API_URL), server-side signing of payment payloads (HMAC-SHA512), a server checkout endpoint that returns apiUrl and formFields for submitting purchases, client checkout invocation (AbaPayway.checkout()), and callback/reconciliation handling. These are specific tools and flows to initiate and process financial transactions (payment gateway integration), not generic automation or API callers. Therefore it grants Direct Financial Execution capability.
Audit Metadata