interswitch-webhooks
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly and narrowly about a payment gateway integration (Interswitch / Quickteller). It defines webhook endpoints, signature verification with a webhook secret (HmacSHA512), and handlers for transaction, subscription, payment-link, and invoice events (e.g., TRANSACTION.COMPLETED, SUBSCRIPTION.TRANSACTION_SUCCESSFUL, INVOICE.PAID). This is a specific financial integration (payment gateway) used to process payment confirmations and lifecycle events and to trigger fulfillment or subscription actions. Under the rules, a skill specifically designed around a payment gateway counts as Direct Financial Execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata