payment-integration

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a payment-integration toolkit for specific payment gateways (SePay, Polar, Stripe, Paddle, Creem.io) and includes gateway-specific APIs/endpoints, checkout session generation, transaction endpoints, subscription management, QR payments, revenue splits, and scripts for webhook verification and checkout creation. These are direct financial execution capabilities (payment processing, creating checkout sessions, handling transactions/subscriptions, splitting revenue) rather than generic tooling. This matches the "Payment Gateways / send transaction / manage subscriptions" criteria for Direct Financial Execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:53 PM