payram-analytics
Warn
Audited by Snyk on Feb 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is PayRam-specific (a payment platform) and exposes named PayRam API tools — not generic HTTP callers. It includes functions for payments data (recent transactions, payment search, summaries) and explicitly lists payram_payment_link ("Create payment link for a project"), plus authentication via PAYRAM_ANALYTICS_TOKEN. Because it targets a payment gateway API and includes a payment-link creation endpoint (a payment-related execution capability), this is a specific financial integration rather than a generic tool. Therefore it meets the criteria for direct financial execution authority.
Audit Metadata