portaly-payment

Warn

Audited by Snyk on May 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. This skill is explicitly designed for payment processing and merchant billing management. It instructs the agent to use a Portaly Vibe Payment API key to perform server-to-server, authenticated money-related operations: create checkout sessions (which result in charges), create/update plans and discount codes, manually complete checkout sessions, and call subscription lifecycle endpoints (POST /subscriptions/{id}/cancel and /resume). The doc also describes persisting payment/order records and verifying callbacks. These are specific payment gateway operations (authorization, charge/session creation, subscription management), not generic tooling—so it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 8, 2026, 08:20 AM
Issues
1