stripe-tax

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is a dedicated Stripe Tax integration (explicitly referencing Stripe and Stripe Tax docs) and exposes a Membrane connector for running actions and proxying requests to the Stripe Tax API. It includes commands to connect to Stripe, run actions (with JSON input), and send HTTP methods including POST/DELETE via the proxy — i.e., it is specifically designed to interact with a payment gateway API and can perform state-changing API calls. Under the policy, Stripe (a payment gateway) integrations count as direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 04:10 PM
Issues
1