payram-payment-integration

Warn

Audited by Snyk on Feb 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is explicitly a self-hosted crypto payment gateway with concrete APIs/SDK calls that move money: e.g., payram.payments.initiatePayment, HTTP POST /api/v1/payment with API keys, webhook handlers for payment fulfillment, and separate "payram-payouts" / "payram-bitcoin-payments" functionality for sending payouts and signing transactions. It is a purpose-built payment integration (drop-in replacement for Stripe/PayPal) for accepting and sending cryptocurrency, so it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 21, 2026, 01:48 PM