sales-checkout
Warn
Audited by Snyk on Apr 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly about checkout/payment processing and repeatedly references specific payment gateways and payment operations: Stripe Checkout, Stripe, PayPal, Apple Pay/Google Pay, Paddle, GrooveSell payment integrations, configuring payment plans, dunning/retrying failed payments, webhook events like purchase_completed/payment_failed, refund processing, and merchant-of-record behavior. These are concrete payment gateway integrations and payment-management actions (connecting processors, configuring subscriptions/payment plans, handling refunds and retries), which constitute direct financial execution capability per the rule (Payment Gateways / payment operations). This is not a generic tool — its primary, explicit purpose is to move/handle money during checkout.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata