NYC

payment-integration

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for payment processing and names concrete payment gateway integrations (stripe, paypal, square, razorpay, braintree) in its MCP Tool Suite. The prompt specifies transaction processing abilities (authorization, capture, void, refunds, partial refunds, settlement reconciliation), token management, webhook handling, and other gateway-specific behaviors. These are specific financial execution capabilities (payment gateways and transaction operations), not generic tools, and therefore enable the agent to move money or perform payment operations directly.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:06 AM