payram-payment-integration

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a crypto payment gateway and includes concrete APIs/SDK calls for creating and managing payments (e.g., payram.payments.initiatePayment, REST POST /api/v1/payment with API keys), webhook handlers to fulfill orders on payment completion, and separate modules for payouts and bitcoin signing (payram-payouts, payram-bitcoin-payments). It is specifically designed to accept and send cryptocurrency (USDT, USDC, BTC, ETH) and to perform payment/payout operations — i.e., it directly enables moving money. This meets the "Direct Financial Execution" criteria.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 08:25 AM