interswitch-vas

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly integrates with the Interswitch Quickteller VAS payment API and includes concrete functions and endpoints that initiate real transactions: e.g., POST /api/v2/quickteller/payments/advices (sendPayment) and POST /api/v2/quickteller/payments/recharges (rechargeAirtime). These functions accept amounts, payment codes, customer IDs, terminalId and requestReference and return transaction references and recharge PINs — i.e., they are designed to execute payments/airtime top-ups. This is a specific payment gateway integration (Direct Financial Execution).

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 03:22 PM
Issues
1