bakong-khqr
Warn
Audited by Snyk on Feb 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a payment integration for Bakong KHQR. It defines Open API endpoints for token lifecycle (POST /v1/request_token, /v1/verify, /v1/renew_token), transaction-status checks (POST /v1/check_transaction_by_md5, /v1/check_transaction_by_hash, /v1/check_transaction_by_short_hash), deeplink/QR generation (POST /v1/generate_deeplink_by_qr) and account checks (POST /v1/check_bakong_account). These are specific, purpose-built payment operations (generating/validating payment QR codes, polling payment status, managing auth tokens) — i.e., direct financial execution capabilities, not a generic tool.
Audit Metadata