payment-integration

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly and specifically designed for payment operations: it names payment gateways (Stripe, PayPal, Square), requires "Stripe/PayPal/Square API integration", covers checkout flows, subscription billing/recurring payments, webhook handling, and mandates server-side verification and use of official SDKs. The outputs include payment integration code and webhook endpoint implementations (i.e., code that would call provider APIs to create charges, manage subscriptions, handle refunds/status). This is not a generic tool—its primary purpose is to execute and manage financial transactions via payment provider APIs. Therefore it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 09:42 PM