check-btcpay

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly about a payment processor (BTCPay Server) and includes direct, specific interactions with its Greenfield API (store listing, payment-methods, webhooks), lightning node checks, and wallet custody indicators (xprv/seed/mnemonic, xpub). Although described as an audit/report primitive (read-only), it targets crypto/payment infrastructure and uses concrete payment/crypto APIs and artifacts rather than generic tooling. Under the rule that flags skills containing specific payment gateway / crypto wallet API interactions, this is a direct financial-related capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:20 AM