NYC

finance-expert

Warn

Audited by Snyk on Feb 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly integrates payment and banking APIs and includes code that performs monetary actions. It contains concrete Stripe operations (create_payment_intent, process_refund, stripe.Token.create, webhook handling) which create payment intents and issue refunds, and Plaid banking integrations (create_link_token, exchange_public_token, get_accounts, get_transactions) that obtain bank access tokens. Those are specific, purpose-built financial tools for processing payments and interacting with bank accounts — i.e., direct financial execution capabilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 10:21 PM