portaly-payment
Warn
Audited by Snyk on May 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Yes. This skill is explicitly designed for payment processing and merchant billing management. It instructs the agent to use a Portaly Vibe Payment API key to perform server-to-server, authenticated money-related operations: create checkout sessions (which result in charges), create/update plans and discount codes, manually complete checkout sessions, and call subscription lifecycle endpoints (POST /subscriptions/{id}/cancel and /resume). The doc also describes persisting payment/order records and verifying callbacks. These are specific payment gateway operations (authorization, charge/session creation, subscription management), not generic tooling—so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata