rye-overview

Warn

Audited by Snyk on Mar 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly describes APIs and workflows that perform purchases: a GET product lookup plus a POST /api/v1/checkout-intents to "purchase it", including a "single-step — One API call, fire-and-forget" path. Use cases call out "An LLM agent that finds products and buys them on behalf of users", "Automated purchasing", and "Programmatic restocking" — all are explicit financial execution actions (placing orders/moving money). It also references production API keys and a Stripe publishable key swap, reinforcing that this is a checkout/payment integration rather than a generic tool. These are specific payment/checkout capabilities, so this is Direct Financial Execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 2, 2026, 06:57 AM