marketing-status
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly integrates with Stripe: it includes "Stripe via CLI" examples (stripe subscriptions list, balance_transactions list), and MCP configuration showing an @stripe/mcp entry with STRIPE_SECRET_KEY and "--tools=all". That is a direct payment-gateway integration (requires secret API key) and therefore grants the agent potential direct access to a payment API (which can perform transactional/write operations, not just read metrics). Even though the skill's purpose is marketing metrics, the explicit Stripe integration (a payment gateway) meets the criteria for Direct Financial Execution risk.
Audit Metadata